dhis2 dhis2-core是dhis2组织的一个应用服务器软件。 dhis2-core 2.37版本、2.38版本和2.39版本存在SQL注入漏洞,该漏洞源于SQL View数据端点允许经过身份验证的用户提供特制筛选值,这些值被插值到生成的SQL中,可能导致经过身份验证的用户操纵SQL并访问预期SQL View结果集之外的数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dhis2 | dhis2-core | = 2.37 |
affected |
= 2.38 |
affected | ||
= 2.39 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dhis2 | dhis2-core | = 2.37 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55084 | 8.8 HIGH | SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read |
| CVE-2026-55081 | DHIS2 Reflected XSS in OpenAPI HTML scope parameter |
No comments yet