PT-2022-16922 · Dhis2 · Dhis2

Philip-Larsen-Donnelly

·

Published

2022-06-01

·

Updated

2022-06-08

·

CVE-2022-24848

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DHIS2 versions prior to 2.36.10.1 and 2.37.6.1
Description DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security issue affects the "/api/programs/orgUnits?programs=" API endpoint. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the issue without first being logged in as a DHIS2 user. The issue is not exposed to a non-malicious user and requires a conscious attack to be exploited. A successful exploit could allow the malicious user to read, edit and delete data in the DHIS2 instance's database.
Recommendations For DHIS2 versions prior to 2.36.10.1, update to version 2.36.10.1 to resolve the issue. For DHIS2 versions prior to 2.37.6.1, update to version 2.37.6.1 to resolve the issue. As a temporary workaround, consider applying mitigations at the web proxy level.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24848
GHSA-52VP-F7HJ-CJ92

Affected Products

Dhis2