Impact
The DHIS2 OpenAPI HTML endpoint reflects the value of the scope query parameter into the generated HTML without proper sanitization, a flaw classified as CWE‑79 (Cross‑Site Scripting). A maliciously crafted scope value can be executed as active HTML or JavaScript when a user visits the page. The potential consequences—such as cookie theft, phishing, tampering of content, or redirection—are inferred from the nature of the flaw.
Affected Systems
The vulnerability affects DHIS2 community releases 2.42 and 2.43 prior to the 2026‑06‑09 security patch, as well as the development branch of DHIS2 2.44 before the fix was merged. The patched versions are DHIS2 2.42.5.1, 2.43.0.1, and the updated 2.44 development branch.
Risk and Exploitability
With a CVSS score of 7.3 the flaw is considered high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low to moderate likelihood of exploitation at present. The attack requires a user to open a crafted OpenAPI URL, so it relies on user interaction and is a client‑side XSS rather than a server‑side attack.
OpenCVE Enrichment