Pi-hole before 6 allows unauthenticated admin/api.php...
High severity
Unreviewed
Published
Aug 19, 2024
to the GitHub Advisory Database
•
Updated Oct 30, 2024
Description
Published by the National Vulnerability Database
Aug 19, 2024
Published to the GitHub Advisory Database
Aug 19, 2024
Last updated
Oct 30, 2024
Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value (Celsius, Fahrenheit, or Kelvin), seen by the device owner, is unclear.
References