Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
| Software | From | Fixed in |
|---|---|---|
| pi-hole / ftldns | 5.7 | 5.7.x |
| pi-hole / pi-hole | 5.2.4 | 5.2.4.x |
| pi-hole / web_interface | - | 5.5 |