React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version 7.13.0.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Shopify React-Router
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
|
6.30.2
|
<= 6.30.4
|
|
Shopify React-Router
cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
|
7.9.6
|
7.13.0
|