vendor:
PiHole
by:
kv1to
N/A
CVSS
N/A
Broken Access Control
Unknown
CWE
Product Name: PiHole
Affected Version From: Pi-hole v5.14.2; FTL v5.19.2; Web Interface v5.17
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2022-23513
CPE: Unknown
Platforms Tested: Raspbian / Debian
2022
AdminLTE PiHole < 5.18 - Broken Access Control
In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on queryads endpoint.
Mitigation:
Unknown