CVE-2026-55084 | DHIS2 up to 2.43.0 SqlView API endpoint api/sqlViews/data.json filter sql injection (PR #24162)

SecurityVulns

A vulnerability, which was classified as critical, was found in DHIS2 up to 2.43.0. Impacted is an unknown function of the file api/sqlViews/data.json of the component SqlView API endpoint. The manipulation of the argument filter results in sql injection.

This vulnerability is reported as CVE-2026-55084. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More