Security Advisory

CVE-2024-44069

7.5
HIGH

Vulnerability Description

Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value (Celsius, Fahrenheit, or Kelvin), seen by the device owner, is unclear.
Published Date August 19, 2024
Official Source NIST NVD Advisory