CVE-2018-25111: Medium severity django helpdesk vulnerability
Published May 31, 2025
·Updated
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
Affected Software
3 affected componentsFixes available
Django Helpdesk Django Helpdesk<1.0.0
pip/django-helpdesk<1.0.0
1.0.0
Django-helpdesk Project Django-helpdesk<1.0.0
Remediation
Patch Available
Event History
May 31, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyAffected Software
Advisory Published
via GitHub·03:30 AM
Data Sourced
via GitHub·03:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-25111?
CVE-2018-25111 has a severity rating that indicates a risk of sensitive data exposure.
2
How do I fix CVE-2018-25111?
To resolve CVE-2018-25111, upgrade to Django Helpdesk version 1.0.0 or later.
3
What kind of data is exposed by CVE-2018-25111?
CVE-2018-25111 can result in exposure of sensitive data due to improper file permissions.
4
Which version of Django Helpdesk is affected by CVE-2018-25111?
Django Helpdesk versions before 1.0.0 are affected by CVE-2018-25111.
5
Is CVE-2018-25111 a remote exploit?
CVE-2018-25111 does not involve remote exploitation, but it can compromise data confidentiality.