CVE-2025-43865
HIGH
Published 2025-04-25T00:18:53.222Z
Actions:
CVSS Score
V3.1
8.2
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score Metrics
Exploitability: N/A
Impact: N/A
Attack Vector Metrics
Impact Metrics
Description
React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values of the data object passed to the HTML. This issue has been patched in version 7.5.2.
Available Exploits
No exploits available for this CVE.
Related News
React Router Vulnerabilities CVE-2025-43864 and CVE-2025-43865 Expose Web Applications to Attack
The React Router team has issued the advisory addressing two vulnerabilities affecting applications running in Framework mode: CVE-2025-43864 The post React Router Vulnerabilities CVE-2025-43864 and CVE-2025-43865 Expose Web Applications to Attack appeared first on Daily CyberSecurity.
SecurityOnline.info
2025-04-28 00:40
Affected Products
Affected Versions:
References
Published: 2025-04-25T00:18:53.222Z
Last Modified: 2025-04-25T15:16:00.202Z
Copied to clipboard!