CVE-2022-23513 is a broken access control vulnerability affecting Pi-hole AdminLTE versions, allowing unauthorized queries for blocked domains. An unauthenticated attacker can exploit this flaw via the /admin/scripts/pi-hole/phpqueryads.php endpoint due to insufficient validation, potentially disclosing a victim's personal blacklists. Rated 5.3 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N), this vulnerability requires no user interaction and has low attack complexity. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, an ExploitDB entry (EDB-51705) exists, indicating public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.17CPE matchmatch criteria | cpe:2.3:a:pi-hole:adminlte:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.