CVE-2022-41948 is a privilege escalation vulnerability affecting DHIS2 versions 2.36.12 and earlier, 2.37.8 and earlier, 2.38.2 and earlier, and 2.39.0 and earlier. An authenticated user with user management authority can craft an HTTP PUT request to assign superuser privileges to themselves. This vulnerability has a CVSS score of 7.2 (High), indicating a high impact on confidentiality, integrity, and availability, with a network attack vector and low attack complexity. While the vulnerability is not currently listed on the KEV catalog and lacks public exploit code or significant community discussion, it allows for complete system compromise if exploited. Administrators should upgrade to hotfix releases 2.36.12.1, 2.37.8.1, 2.38.2.1, or 2.39.0.1, or temporarily revoke user management authority as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.34.0, < 2.36.12.1CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* | ||
>= 2.37.0, < 2.37.8.1CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* | ||
>= 2.38.0, < 2.38.2.1CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:*:*:*:*:*:*:*:* | ||
2.39.0CPE matchmatch criteria | cpe:2.3:a:dhis2:dhis_2:2.39.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.