cvedb.io
CVE-2022-41947
MEDIUM · CVSS 5.4
EPSS exploitation probability: 0%
Published 2022-12-08T23:15:10.813 · Last modified 2026-06-17T05:04:07.003

Summary

DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Through various features of DHIS2, an authenticated user may be able to upload a file which includes embedded javascript. The user could then potentially trick another authenticated user to open the malicious file in a browser which would trigger the javascript code, resulting in a cross-site scripting (XSS) attack. DHIS2 administrators should upgrade to the following hotfix releases: 2.36.12.1, 2.37.8.1, 2.38.2.1, 2.39.0.1. Users unable to upgrade may add the following simple CSP rule in your web proxy to the vulnerable endpoints: `script-src 'none'`. This workaround will prevent all javascript from running on those endpoints.

Affected products

dhis2 — dhis_2

Does this affect you?

Add your gear to cvedb and we'll alert you only when dhis2 ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.