CVE-2021-3950: Cross-site Scripting (XSS) - Stored in django-helpdesk/django-helpdesk
Published Nov 19, 2021
·Updated
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
2 affected componentsFixes available
pip/django-helpdesk<0.3.2
0.3.2
Django-helpdesk Project Django-helpdesk<0.3.1
Remediation
Event History
Nov 19, 2021
CVE Published
via MITRE·12:10 PM
Data Sourced
via MITRE·12:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 23, 2021
Advisory Published
via GitHub·05:55 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-3950?
CVE-2021-3950 is categorized as a moderate severity vulnerability due to its potential for Cross-site Scripting (XSS).
2
How do I fix CVE-2021-3950?
To fix CVE-2021-3950, upgrade django-helpdesk to version 0.3.2 or later.
3
What software is affected by CVE-2021-3950?
CVE-2021-3950 affects django-helpdesk versions prior to 0.3.2.
4
What type of vulnerability is CVE-2021-3950?
CVE-2021-3950 is an example of Improper Neutralization of Input During Web Page Generation, commonly known as Cross-site Scripting (XSS).
5
Is there a known exploit for CVE-2021-3950?
As of the last update, there are no public exploits specifically targeting CVE-2021-3950.