CVE-2022-24848: SQL Injection in DHIS2's in OrgUnit program association
DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the /api/programs/orgUnits?programs= API endpoint in DHIS2 versions prior to 2.36.10.1 and 2.37.6.1. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user and requires a conscious attack to be exploited. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance's database. Security patches are now available for DHIS2 versions 2.36.10.1 and 2.37.6.1. One may apply mitigations at the web proxy level as a workaround. More information about these mitigations is available in the GitHub Security Advisory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24848?
CVE-2022-24848 has a high severity rating due to its potential impact on data integrity through SQL injection.
How do I fix CVE-2022-24848?
To fix CVE-2022-24848, upgrade to DHIS2 version 2.36.10.1 or 2.37.6.1 or later.
Which DHIS2 versions are affected by CVE-2022-24848?
CVE-2022-24848 affects DHIS2 versions prior to 2.36.10.1 and versions between 2.37.0 and 2.37.6.1.
What type of vulnerability is CVE-2022-24848?
CVE-2022-24848 is a SQL injection vulnerability that allows attackers to manipulate database queries.
Where does CVE-2022-24848 occur in DHIS2?
CVE-2022-24848 occurs in the /api/programs/orgUnits?programs= API endpoint of DHIS2.