PyPI package
django-helpdesk
pkg:pypi/django-helpdesk
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-25111 | — | < 1.0.0 | 1.0.0 | May 31, 2025 | django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py. | ||
| CVE-2021-3994 | — | < 0.3.2 | 0.3.2 | Dec 1, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-3950 | — | < 0.3.2 | 0.3.2 | Nov 19, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-3945 | — | < 0.3.1 | 0.3.1 | Nov 13, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- CVE-2018-25111May 31, 2025affected < 1.0.0fixed 1.0.0
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
- CVE-2021-3994Dec 1, 2021affected < 0.3.2fixed 0.3.2
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-3950Nov 19, 2021affected < 0.3.2fixed 0.3.2
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-3945Nov 13, 2021affected < 0.3.1fixed 0.3.1
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')