cvedb.io
CVE-2022-23513
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2022-12-23T00:15:08.747 · Last modified 2026-06-17T04:30:16.493

Summary

Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path: `/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.

Affected products

pi-hole — adminlte

Does this affect you?

Add your gear to cvedb and we'll alert you only when pi-hole ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.