CVE-2018-15685

6.8
MEDIUMCVSS v2
Published
August 23, 2018
Affected
2 projects
Assigned by
MITRE
Severity scale
010

Description

GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.

electron/electron
electron/electron
GitHubGitHub:electron: Build cross-platform desktop apps with JavaScript, HTML, and CSS
= 3.0.0, = 2.0.7, = 1.8.7, = 1.7.15NVD
electron
electron
NPMNPMBuild cross platform desktop apps with JavaScript, HTML, and CSS
= 3.0.0, = 2.0.7, = 1.8.7, = 1.7.15NVD

More on this CVE