CVE-2025-48383
Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget can leak secret access tokens across requests. This can allow users to access restricted query sets and restricted data. This issue has been patched in version 8.4.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.31%
- CWE
- CWE-402, CWE-918
- Published
- 2025-05-27
- Last modified
- 2026-03-13
Affected products
- codingjoe django-select2
Weakness type
Related vulnerabilities
- CVE-2025-67745 — Myhoard logs backup encryption key in plain text
- CVE-2025-66422 — Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup)...
- CVE-2025-55014 — The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and...
- CVE-2025-49618 — In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId,...
- CVE-2025-52925 — In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken...
- CVE-2025-32360 — In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and...
- CVE-2025-29925 — XWiki allows unregistered users to access private pages information through REST endpoint
- CVE-2025-0502 — Transmission of Private Resources into a New Sphere in Crafter Engine