CVE-2022-24848: SQL Injection in DHIS2's in OrgUnit program association

Published Jun 1, 2022
·
Updated

DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the /api/programs/orgUnits?programs= API endpoint in DHIS2 versions prior to 2.36.10.1 and 2.37.6.1. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user and requires a conscious attack to be exploited. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance's database. Security patches are now available for DHIS2 versions 2.36.10.1 and 2.37.6.1. One may apply mitigations at the web proxy level as a workaround. More information about these mitigations is available in the GitHub Security Advisory.

Affected Software

2 affected components
DHIS2 DHIS 2<2.36.10.1
DHIS2 DHIS 2>=2.37.0<2.37.6.1

Event History

Jun 1, 2022
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2022-24848?

CVE-2022-24848 has a high severity rating due to its potential impact on data integrity through SQL injection.

2

How do I fix CVE-2022-24848?

To fix CVE-2022-24848, upgrade to DHIS2 version 2.36.10.1 or 2.37.6.1 or later.

3

Which DHIS2 versions are affected by CVE-2022-24848?

CVE-2022-24848 affects DHIS2 versions prior to 2.36.10.1 and versions between 2.37.0 and 2.37.6.1.

4

What type of vulnerability is CVE-2022-24848?

CVE-2022-24848 is a SQL injection vulnerability that allows attackers to manipulate database queries.

5

Where does CVE-2022-24848 occur in DHIS2?

CVE-2022-24848 occurs in the /api/programs/orgUnits?programs= API endpoint of DHIS2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203