CVE-2020-11108: Pi-Hole
High severity, CVSS 8.8. EPSS: 78.3% chance of exploitation in the next 30 days.
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.
Affected products
- Pi-hole Pi-Hole: up to and including 4.4
Published 2020-05-11. Last modified 2026-06-17.