PT-2026-62034 · Dhis2 · Dhis2

CVE-2026-55081

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

7.3

High

VectorAV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions DHIS2 versions 2.42 through 2.42.5.0 DHIS2 versions 2.43 through 2.43.0.0 DHIS2 version 2.44 (development branch)
Description The OpenAPI HTML endpoint reflects values from the scope query parameter into the generated HTML document without sufficient sanitization. This allows a crafted scope value to be rendered as active HTML or JavaScript on the OpenAPI documentation page. An attacker could trick a user into opening a specially crafted URL to execute JavaScript within the user's browser in the DHIS2 origin.
Recommendations Update to version 2.42.5.1. Update to version 2.43.0.1. Update the 2.44 development branch to the version where the fix was merged.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55081
GHSA-6785-HJ47-C27H

Affected Products

Dhis2