The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query Log page.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-23322 The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query Log page.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T17:09:14.618Z

Reserved: 2020-12-23T00:00:00

Link: CVE-2020-35659

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-24T16:15:15.490

Modified: 2024-11-21T05:27:47.110

Link: CVE-2020-35659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses