In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adguardhome | Adguard | 0.95 (including) | 0.108 (excluding) |
Adguardhome | Adguard | 0.108 (including) | 0.108 (including) |
Adguardhome | Adguard | 0.108-beta1 (including) | 0.108-beta1 (including) |
Adguardhome | Adguard | 0.108-beta10 (including) | 0.108-beta10 (including) |
Adguardhome | Adguard | 0.108-beta11 (including) | 0.108-beta11 (including) |
Adguardhome | Adguard | 0.108-beta12 (including) | 0.108-beta12 (including) |
Adguardhome | Adguard | 0.108-beta2 (including) | 0.108-beta2 (including) |
Adguardhome | Adguard | 0.108-beta3 (including) | 0.108-beta3 (including) |
Adguardhome | Adguard | 0.108-beta4 (including) | 0.108-beta4 (including) |
Adguardhome | Adguard | 0.108-beta5 (including) | 0.108-beta5 (including) |
Adguardhome | Adguard | 0.108-beta6 (including) | 0.108-beta6 (including) |
Adguardhome | Adguard | 0.108-beta7 (including) | 0.108-beta7 (including) |
Adguardhome | Adguard | 0.108-beta8 (including) | 0.108-beta8 (including) |
Adguardhome | Adguard | 0.108-beta9 (including) | 0.108-beta9 (including) |