Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-39179

Опубликовано: 29 окт. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execute arbitrary SQL commands via unspecified vectors. This vulnerability affects the /api/trackedEntityInstances and /api/trackedEntityInstances/query API endpoints in all DHIS2 versions 2.34, 2.35, and 2.36. It also affects versions 2.32 and 2.33 which have reached end of support - exceptional security updates have been added to the latest end of support builds for these versions. Versions 2.31 and older are unaffected. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user - the vulnerability requires a conscious attack to be exploited. A successful exploit of this vulnerability

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:*
Версия от 2.32.0 (включая) до 2.32.7 (включая)
cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:*
Версия от 2.33.0 (включая) до 2.33.9 (включая)
cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:*
Версия от 2.35.0 (включая) до 2.35.7 (исключая)
cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:*
Версия от 2.36.0 (включая) до 2.36.4 (исключая)

EPSS

Процентиль: 72%
0.00727
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89

EPSS

Процентиль: 72%
0.00727
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89