Dhis2

Dhis 2

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 09.05.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:01:28

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, using object model traversal in the payload of a PATCH request, a...

  • EPSS 0.07%
  • Veröffentlicht 09.05.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:01:28

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.1.2, Personal Access Tokens (PATs) generate unrestricted session cooki...

  • EPSS 0.11%
  • Veröffentlicht 09.05.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:02:38

DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and 2.39.0, when the Category Option Combination Sharing settings are conf...

  • EPSS 0.22%
  • Veröffentlicht 08.12.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:07

DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Through various features of DHIS2, an authenticated user may be able to upload a file which includes embedded javascript. The user coul...

  • EPSS 0.34%
  • Veröffentlicht 08.12.2022 23:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:08

DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerability. A DHIS2 user with authority to manage users can assign superuser...

  • EPSS 0.14%
  • Veröffentlicht 08.12.2022 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:08

DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. In affected versions an authenticated DHIS2 user can craft a request to DHIS2 to instruct the server to make requests to external resou...

  • EPSS 0.46%
  • Veröffentlicht 01.06.2022 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:13

DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?programs=` API endpoint in DHIS2 versions prior to 2.36.10.1 and 2.37.6.1...

  • EPSS 0.23%
  • Veröffentlicht 01.11.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:43

DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the API endpoints for /api/trackedE...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 29.10.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:48

DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execute arbitrary SQL commands via ...

  • EPSS 0.26%
  • Veröffentlicht 24.06.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:33

DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the /api/trackedEntityInstances API...