Dhis2 / Dhis 2
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-32060 | DHIS2 Core Improper Access Control with Category Option Combination sharing in /api/trackedEntityInstance and /api/events | MEDIUM | 6.5 | May 9, 2023 |
| CVE-2023-31139 | DHIS2 Core unrestricted session cookies with Personal Access Tokens | HIGH | 7.5 | May 9, 2023 |
| CVE-2023-31138 | DHIS2 Core vulnerable to Improper Access Control with PATCH requests | HIGH | 7.1 | May 9, 2023 |
| CVE-2022-41947 | Cross-site Scripting with user-uploaded files in dhis2-core | MEDIUM | 5.4 | Dec 8, 2022 |
| CVE-2022-41948 | Privilege Chaining with the user admin role in dhis2-core | HIGH | 7.2 | Dec 8, 2022 |
| CVE-2022-41949 | Semi-blind Server-Side Request Forgery in dhis2-core | MEDIUM | 5.0 | Dec 8, 2022 |
| CVE-2022-24848 | SQL Injection in DHIS2's in OrgUnit program association | HIGH | 8.8 | Jun 1, 2022 |
| CVE-2021-41187 | SQL Injection in DHIS2 Tracker API | HIGH | 8.8 | Nov 1, 2021 |
| CVE-2021-39179 | SQL Injection in DHIS2 Tracker API | HIGH | 8.8 | Oct 29, 2021 |
| CVE-2021-32704 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in dhis2-core | HIGH | 8.8 | Jun 24, 2021 |
Showing 1 to 10 of 10 CVEs