CVE-2020-35592
Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the session cookie.
- Affected products
- Pi-Hole
- Pi-hole
- = 5.0, 5.1, 5.1.1
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.9% (55th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-02-18
CVE-2020-35592 at NVD
No indexed exploits for CVE-2020-35592 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-35592 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.