vendor:
Electron
by:
Matt
8.1
CVSS
HIGH
Remote Code Execution
20
CWE
Product Name: Electron
Affected Version From: 3.0.0-beta.6
Affected Version To: 1.7.15
Patch Exists: YES
Related CWE: CVE-2018-15685
CPE: electron
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2018
CVE-2018-15685 – Electron WebPreferences Remote Code Execution
A remote code execution vulnerability has been discovered affecting apps with the ability to open nested child windows on Electron versions (3.0.0-beta.6, 2.0.7, 1.8.7, and 1.7.15). This vulnerability has been assigned the CVE identifier CVE-2018-15685.
Mitigation:
Electron has released a patch for this vulnerability. Users should upgrade to the latest version of Electron.