Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the session cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pi-hole 跨站脚本漏洞
Vulnerability Description
Pi-hole是Pi-hole公司的一款网络级广告拦截应用程序。 Pi-hole 中存在跨站脚本漏洞。该漏洞源于可通过Options头指向admin/URI,对用户提供的数据进行了不正确的清理,远程用户能够注入任意web脚本或HTML,并对其他用户实施反射式跨站点脚本攻击,窃取会话cookie。以下产品及版本受到影响:Pi-hole 5.0, Pi-hole 5.1, Pi-hole 5.1.1。
CVSS Information
N/A
Vulnerability Type
N/A