← volver
CVE-2021-32706highCWE-94

(Authenticated) Remote Code Execution Possible in Web Interface 5.5

48Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 7.6epss 60%
de la publicación al arma0 días
Publicada en NVD4 ago
metasploit4 ago
probabilidad de explotación
60%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. The issue lies in the fact that one of the periods is not escaped, allowing any character to be used in its place. A patch for this vulnerability was released in version 5.5.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Productos afectados
pi-hole · AdminLTE