vendor:
Pi-hole
by:
Luis Vacas
7.2
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Pi-hole
Affected Version From: 4.3.2
Affected Version To: 4.3.2
Patch Exists: YES
Related CWE: CVE-2020-8816
CPE: a:pi-hole:pi-hole
Other Scripts:
N/A
Platforms Tested: Ubuntu 19.10
2020
Pi-hole 4.3.2 – Remote Code Execution (Authenticated)
A vulnerability in Pi-hole 4.3.2 allows an authenticated user to execute arbitrary code on the target system. This is due to the lack of proper input validation in the log.php script. An attacker can send a specially crafted request to the log.php script to execute arbitrary code on the target system.
Mitigation:
Upgrade to the latest version of Pi-hole.