CVE-2021-41187 is a high-severity SQL injection vulnerability affecting specific versions of DHIS2 (2.32-2.36), specifically within the /api/trackedEntityInstances and /api/events API endpoints. This flaw allows authenticated users to read, edit, and delete data within the DHIS2 instance. With a CVSS score of 8.8, it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there are no known active exploits, public exploit code, or significant community discussion, immediate patching is strongly recommended as a straightforward workaround is unavailable for systems utilizing Tracker functionality.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.32.0, <= 2.32.7CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* | ||
>= 2.33.0, <= 2.33.9CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* | ||
>= 2.34.0, <= 2.34.6CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* | ||
>= 2.35.0, <= 2.35.7CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* | ||
>= 2.36.0, <= 2.36.3CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.