nystudio107/craft-retour is vulnerable to Cross-Site Scripting
50
Medium Risk
Affected versions of craft-retour are vulnerable to Cross-site Scripting (XSS) via the HTTP Referer header.
You are affected if you use a vulnerable version of craft-retour.
nystudio107/craft-retour is vulnerable to Cross-Site Scripting in versions 4.0.0 - 4.1.12 and 3.0.0 - 3.2.11.
Upgrade craft-retour to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant