Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code, list directories, and overwrite sensitive files. The issue lies in the fact that one of the periods is not escaped, allowing any character to be used in its place. A patch for this vulnerability was released in version 5.5.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2021-08-04T17:50:09
Updated: 2024-08-03T23:25:31.137Z
Reserved: 2021-05-12T00:00:00
Link: CVE-2021-32706
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-08-04T18:15:09.447
Modified: 2024-11-21T06:07:34.203
Link: CVE-2021-32706
Redhat
No data.