DHIS 2是一个应用软件。一个灵活的信息系统,用于数据捕获、管理、验证、分析和可视化。 DHIS 2 2.37.9.1之前版本、2.38.3.1 之前版本和 2.39.1.2 之前版本存在安全漏洞,该漏洞源于在 PATCH 请求的负载中使用对象模型遍历,对对象具有写访问权限的用户可能能够修改相关对象。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dhis2 | dhis2-core | >= 2.36, < 2.37.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-32060 | 6.5 MEDIUM | DHIS2 Core Improper Access Control with Category Option Combination sharing in /api/tracke |
| CVE-2023-31139 | 4.3 MEDIUM | DHIS2 Core unrestricted session cookies with Personal Access Tokens |
No comments yet