PyPI package
django-helpdesk
pkg:pypi/django-helpdesk
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-25111 | Med | 5.1 | < 1.0.0 | 1.0.0 | May 31, 2025 | django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py. | |
| CVE-2021-3994 | Cri | 9.6 | < 0.3.2 | 0.3.2 | Dec 1, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2021-3950 | Med | 5.4 | < 0.3.2 | 0.3.2 | Nov 19, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| CVE-2021-3945 | Med | 6.1 | < 0.3.1 | 0.3.1 | Nov 13, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
- affected < 1.0.0fixed 1.0.0
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
- affected < 0.3.2fixed 0.3.2
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- affected < 0.3.2fixed 0.3.2
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- affected < 0.3.1fixed 0.3.1
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')