In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/AdguardTeam/AdGuardHome(Go) | 0.95 | 0.108.0-b.16 | N/A |
CVSS Metrics