Опубликовано: 03 дек. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8
Описание
django-helpdesk is vulnerable to Cross-site Scripting
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-3994
- https://github.com/django-helpdesk/django-helpdesk/commit/a22eb0673fe0b7784f99c6b5fd343b64a6700f06
- https://github.com/advisories/GHSA-2v5j-q74q-r53f
- https://github.com/django-helpdesk/django-helpdesk/releases/tag/0.3.2
- https://github.com/pypa/advisory-database/tree/main/vulns/django-helpdesk/PYSEC-2021-438.yaml
- https://huntr.dev/bounties/be7f211d-4bfd-44fd-91e8-682329906fbd
Пакеты
Наименование
django-helpdesk
pip
Затронутые версииВерсия исправления
< 0.3.2
0.3.2
Связанные уязвимости
CVSS3: 9.6
nvd
около 4 лет назад
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')