django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of sanitization and Content-Disposition headers at the attachment-serving layer to execute malicious scripts in the browser session of authenticated staff members who open the attachment while triaging tickets.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:django-helpdesk_project:django-helpdesk:*:*:*:*:*:*:*:* |
Fri, 14 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Django-helpdesk Project
Django-helpdesk Project django-helpdesk |
|
| Vendors & Products |
Django-helpdesk Project
Django-helpdesk Project django-helpdesk |
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of sanitization and Content-Disposition headers at the attachment-serving layer to execute malicious scripts in the browser session of authenticated staff members who open the attachment while triaging tickets. | |
| Title | django-helpdesk < 2.3.3 Stored XSS via HTML Attachments | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-13T19:06:11.969Z
Updated: 2026-08-14T19:45:18.236Z
Reserved: 2026-08-12T19:29:19.866Z
Link: CVE-2026-73531
Updated: 2026-08-14T18:30:25.844Z
Status : Received
Published: 2026-08-13T20:17:29.747
Modified: 2026-08-14T20:16:57.857
Link: CVE-2026-73531
No data.