dhis2 dhis2-core是dhis2组织的一个应用服务器软件。 dhis2-core存在跨站脚本漏洞,该漏洞源于OpenAPI HTML端点未充分清理 查询参数中的值,可能导致攻击者通过特制URL在用户浏览器中执行JavaScript。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dhis2 | dhis2-core | >= 2.42.0, < 2.42.5.1 |
affected |
>= 2.43.0, < 2.43.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dhis2 | dhis2-core | >= 2.42.0, < 2.42.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55084 | 8.8 HIGH | SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read |
| CVE-2026-55082 | DHIS2 SQL injection in SQL View filter values |
No comments yet