Vulnerabilities
Vulnerable Software
Pi-Hole:  >> Pi-Hole  >> 5.18.2  Security Vulnerabilities
Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value (Celsius, Fahrenheit, or Kelvin), seen by the device owner, is unclear.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-08-19
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.
CVSS Score
8.5
EPSS Score
0.519
Published
2024-07-05


Contact Us

Shodan ® - All rights reserved