CVE-2022-32175
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
11/10/2022
Last modified:
20/05/2025
Description
In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:adguard:adguardhome:*:*:*:*:*:*:*:* | 0.95 (including) | 0.108 (excluding) |
cpe:2.3:a:adguard:adguardhome:0.108:-:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta1:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta10:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta11:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta12:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta2:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta3:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta4:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta5:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta6:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta7:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta8:*:*:*:*:*:* | ||
cpe:2.3:a:adguard:adguardhome:0.108:beta9:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/AdguardTeam/AdGuardHome/blob/v0.108.0-b.13/internal/home/controlfiltering.go#L265
- https://www.mend.io/vulnerability-database/CVE-2022-32175
- https://github.com/AdguardTeam/AdGuardHome/blob/v0.108.0-b.13/internal/home/controlfiltering.go#L265
- https://www.mend.io/vulnerability-database/CVE-2022-32175