Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the session cookie.
| Software | From | Fixed in |
|---|---|---|
| pi-hole / pi-hole | 5.0 | 5.0.x |
| pi-hole / pi-hole | 5.1 | 5.1.x |
| pi-hole / pi-hole | 5.1.1 | 5.1.1.x |