PT-2026-62034 · Dhis2 · Dhis2
CVE-2026-55081
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v4.0
7.3
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DHIS2 versions 2.42 through 2.42.5.0
DHIS2 versions 2.43 through 2.43.0.0
DHIS2 version 2.44 (development branch)
Description
The OpenAPI HTML endpoint reflects values from the
scope query parameter into the generated HTML document without sufficient sanitization. This allows a crafted scope value to be rendered as active HTML or JavaScript on the OpenAPI documentation page. An attacker could trick a user into opening a specially crafted URL to execute JavaScript within the user's browser in the DHIS2 origin.Recommendations
Update to version 2.42.5.1.
Update to version 2.43.0.1.
Update the 2.44 development branch to the version where the fix was merged.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dhis2