CVE-2022-31029
Dashboard / Vulnerabilities / CVE-2022-31029
Summary: Authenticated XSS in Pi-hole AdminLTE
Details: AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XSS")</script>` in the field marked with "Domain to look for" and hitting <kbd>enter</kbd> (or clicking on any of the buttons) will execute the script. The user must be logged in to use this vulnerability. Usually only administrators have login access to pi-hole, minimizing the risks. Users are advised to upgrade. There are no known workarounds for this issue.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31029.json, https://github.com/pi-hole/AdminLTE/security/advisories/GHSA-cfr5-rqm5-9vhp, https://nvd.nist.gov/vuln/detail/CVE-2022-31029, https://github.com/pi-hole/AdminLTE/commit/b07372bd426ca8111824a0244dc89d07a7243509
Affected packages
Package
Name:
Purl:
