CVE-2026-55081
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
21/07/2026
Última modificación:
21/07/2026
Descripción
*** Pendiente de traducción *** DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization. A crafted `scope` value could be rendered as active HTML or JavaScript in the OpenAPI documentation page. An attacker able to get a user to open a crafted OpenAPI HTML URL could execute JavaScript in that user&#39;s browser in the DHIS2 origin.<br />
<br />
Affected versions: DHIS2 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged.<br />
Patched in 2.42.5.1, 2.43.0.1, the 2.42 and 2.43 line branches, and the 2.44 development branch.
Impacto
Puntuación base 4.0
7.30
Gravedad 4.0
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/dhis2/dhis2-core/pull/24158
- https://github.com/dhis2/dhis2-core/pull/24159
- https://github.com/dhis2/dhis2-core/pull/24160
- https://github.com/dhis2/dhis2-core/pull/24161
- https://github.com/dhis2/dhis2-core/pull/24162
- https://github.com/dhis2/dhis2-core/security/advisories/GHSA-6785-hj47-c27h



