HIGH🇵🇱 Wersja polska

CVE-2025-59151

CVSS 8.2v3.1pub. 2025-10-27upd. 2025-12-18

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed (CRLF) injection. When a request is made to a file ending with the .lp extension, the application performs a redirect without properly sanitizing the input. An attacker can inject carriage return and line feed characters (%0d%0a) to manipulate both the headers and the content of the HTTP response. This enables the injection of arbitrary HTTP response headers, potentially leading to session fixation, cache poisoning, and the weakening or bypassing of browser-based security mechanisms such as Content Security Policy or X-XSS-Protection. This vulnerability is fixed in 6.3.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
  • Pi Hole Web Interface

    APP
    Pi-Hole
    < 6.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-33765HIGH8.9same product

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker block...

CVE-2023-23614HIGH8.8same product

Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions ...

CVE-2021-41175HIGH7.3same product

Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the...

CVE-2021-3706HIGH7.5same product

adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag

CVE-2021-29448HIGH7.6same product

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exist...