An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the domain string. These commands are executed on the underlying operating system with the privileges of the Pi-hole service user. This behavior was present in the legacy AdminLTE interface and has since been patched in later versions.
When adding a domain to the allowlist through the AdminLTE interface, the domain parameter is not properly validated or sanitized. An attacker can append additional operating system commands to the domain string (e.g., using shell special characters). The payload passed this way is then forwarded to a system call and executed with the privileges of the user running the Pi-hole service.
An attacker can execute arbitrary commands on the server with the privileges of the Pi-hole process, which may lead to complete system compromise, data theft, or further lateral movement in the network.
Pi-hole should be updated to version 4.0 or later, where the vulnerability has been removed. The patch is available in the repository: https://github.com/pi-hole/web/releases/tag/v4.0
Pi-hole in versions up to and including 3.3 using the AdminLTE interface
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XPi Hole
APPPi-Hole≤ 3.3
Related vulnerabilities
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHC...
Pi-hole: privilege escalation do root przez podmianę pliku logrotate
Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of th...
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side softw...
The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-s...