CVE-2020-14162: Pi-Hole
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell metacharacters to this script's setdns command.
Affected products
- Pi-hole Pi-Hole: before 5.1 (fixed in 5.1)
Published 2020-07-30. Last modified 2026-06-17.