Headline
GHSA-mwwc-3jv2-62j3: AdGuardHome vulnerable to Cross-Site Request Forgery
In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.
The file that contains the vulnerable code is no longer present as of v0.108.0-b.16.
AdGuardHome vulnerable to Cross-Site Request Forgery
Moderate severity GitHub Reviewed Published Oct 11, 2022 • Updated Oct 11, 2022
Related news
In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.