Pi-hole Web Interface是Pi-hole开源的一个仪表板Web界面。 Pi-hole Web Interface 6.2.1及之前版本存在跨站脚本漏洞,该漏洞源于404错误页面未正确清理或转义URL路径,可能导致反射型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Cross-Site-Scripting XSS in Pi-hole-CVE-2025-53533 exploit (PoC) | https://github.com/moezbouzayani9/Pi-hole-XSS-CVE-2025-53533 | POC Details |
| 2 | Pi-hole Admin Interface <= 6.2.1 contains a reflected XSS vulnerability on the 404 error page. The URL path is reflected unsanitized into the `class` attribute of the `body` tag, allowing attribute injection via a crafted URL to execute arbitrary JavaScript in victim browsers. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53533.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-59151 | 8.2 HIGH | Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection |
| CVE-2025-32785 | Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management |
No comments yet