CVE-2018-15685
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.
- Affected products
- Github Electron
- Electronjs Electron
- = 1.7.15, 1.8.7, 2.0.7, 3.0.0
- Fix
- Available
- CVSS 3.0
- 8.1 HIGH
- EPSS
- 9.3% (95th percentile)
- Weakness
- CWE-1188
- NVD status
- Modified
- Published
- 2018-08-23
CVE-2018-15685 at NVD
3 known exploits for CVE-2018-15685
Proof-of-concept code and exploit modules indexed by Sploitus