Skip to content
Noroxi

dhis2 records

10 published records for vendor dhis2.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

10 records
  • SQL Injection in DHIS2 Tracker API

    HighCVSS 8.8No exploitEPSS 2%

    dhis2 · dhis 2Oct 29, 2021

  • SQL Injection in DHIS2's in OrgUnit program association

    HighCVSS 8.8No exploitEPSS 1%

    dhis2 · dhis 2Jun 1, 2022

  • SQL Injection in DHIS2 Tracker API

    HighCVSS 8.8No exploitEPSS 1%

    dhis2 · dhis 2Nov 1, 2021

  • Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in dhis2-core

    HighCVSS 8.8No exploitEPSS 1%

    dhis2 · dhis 2Jun 24, 2021

  • DHIS2 Core unrestricted session cookies with Personal Access Tokens

    HighCVSS 7.5No exploitEPSS 1%

    dhis2 · dhis 2May 9, 2023

  • Privilege Chaining with the user admin role in dhis2-core

    HighCVSS 7.2No exploitEPSS 1%

    dhis2 · dhis 2Dec 8, 2022

  • DHIS2 Core vulnerable to Improper Access Control with PATCH requests

    MediumCVSS 6.5No exploitEPSS 1%

    dhis2 · dhis 2May 9, 2023

  • DHIS2 Core Improper Access Control with Category Option Combination sharing in /api/trackedEntityInstance and /api/events

    MediumCVSS 6.5No exploitEPSS 1%

    dhis2 · dhis 2May 9, 2023

  • Cross-site Scripting with user-uploaded files in dhis2-core

    MediumCVSS 5.4No exploitEPSS 0%

    dhis2 · dhis 2Dec 8, 2022

  • Semi-blind Server-Side Request Forgery in dhis2-core

    MediumCVSS 4.3No exploitEPSS 0%

    dhis2 · dhis 2Dec 8, 2022