Skip to content
This repository has been archived by the owner on Jul 11, 2019. It is now read-only.

Potential remote arbitrary code execution #172

Open
freetom opened this issue Feb 27, 2017 · 0 comments
Open

Potential remote arbitrary code execution #172

freetom opened this issue Feb 27, 2017 · 0 comments

Comments

@freetom
Copy link

freetom commented Feb 27, 2017

Hi, I noted that here the message is directly used to set the value of the innerHTML field of a DOM element without HTML sanitization. When rendered, the element will trigger an XSS injection that in Electron implies arbitrary js code execution (shell commands, etc).

I said "potential" because I am not able to test the chat with anyone. We tried with 2 boxes on the same network but except the 1 peer connected status message we found no way to chat :(

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant