CVE-2021-3994: Cross-site Scripting (XSS) - Stored in django-helpdesk/django-helpdesk
Published Dec 1, 2021
·Updated
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
2 affected componentsFixes available
pip/django-helpdesk<0.3.2
0.3.2
Django-helpdesk Project Django-helpdesk<0.3.2
Remediation
Event History
Dec 1, 2021
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 3, 2021
Advisory Published
via GitHub·08:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-3994?
CVE-2021-3994 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2021-3994?
To fix CVE-2021-3994, upgrade django-helpdesk to version 0.3.2 or later.
3
What type of vulnerability is CVE-2021-3994?
CVE-2021-3994 is an Improper Neutralization of Input During Web Page Generation vulnerability, also known as cross-site scripting.
4
What software is affected by CVE-2021-3994?
CVE-2021-3994 affects all versions of django-helpdesk prior to 0.3.2.
5
What consequences can occur due to CVE-2021-3994?
Exploiting CVE-2021-3994 can allow attackers to inject malicious scripts into web pages viewed by users, compromising user data and session integrity.