CVE-2021-29448
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
- Affected products
- Pi-Hole
- Pi-hole Ftldns
- = 5.7
- Pi-hole
- = 5.2.4
- Pi-hole Web Interface
- < 5.5
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.7% (48th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-04-15
CVE-2021-29448 at NVD
No indexed exploits for CVE-2021-29448 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-29448 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.