CVE-2020-35591
Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's account through the active session.
- Affected products
- Pi-Hole
- Pi-hole
- = 5.0, 5.1, 5.1.1
- CVSS 2.0
- 5.8 MEDIUM
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 1.1% (63th percentile)
- Weakness
- CWE-384
- NVD status
- Modified
- Published
- 2021-02-18
CVE-2020-35591 at NVD
No indexed exploits for CVE-2020-35591 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-35591 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.