CVE-2025-43865

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.
Configurations

No configuration.

History

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) React Router es un enrutador para React. En versiones de la rama 7.0 anteriores a la 7.5.2, es posible modificar datos pre-renderizados añadiendo un encabezado a la solicitud. Esto permite falsificar completamente su contenido y modificar todos los valores del objeto de datos pasado al HTML. Este problema se ha corregido en la versión 7.5.2.

25 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-25 01:15

Updated : 2025-04-29 13:52


NVD link : CVE-2025-43865

Mitre link : CVE-2025-43865

CVE.ORG link : CVE-2025-43865


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity