peter bassill · operator
$ cve CVE-2022-23513 JSON

CVE-2022-23513 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 40.2% (pctl 99)

Patch early

A public exploit exists.

Description

Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path: `/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS40.16% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploityes
Published2022-12-23
Last modified2026-06-17

Affected (1)

VendorProduct
pi-holeadminlte

Public exploits

SourceTitleDate
exploit-dbAdminLTE PiHole 5.18 - Broken Access Control2023-09-04

References

→ the Explorer  ·  watch your stack  ·  NVD