Sploitus

CVE-2020-35592

No indexed exploits for CVE-2020-35592 yet

Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the session cookie.

Affected products
Pi-Hole
Pi-hole
= 5.0, 5.1, 5.1.1
CVSS 3.1
5.4 MEDIUM
EPSS
0.9% (55th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2021-02-18
CVE-2020-35592 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-35592 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-35592 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.