CVE-2026-55084
dhis2 dhis2-core
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the `/api/sqlViews/{viewId}/data.json` endpoint. An authenticated user with access to a SqlView can inject arbitrary SQL queries inside the `filter` parameter by abusing an expression executed by PostgreSQL and its output is reflected inside the application error message. This behavior enables attackers to extract arbitrary database content using error-...
- CVSS
- 8.8
- EPSS
- 0.25% 16.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.22