CVE-2018-8545 describes an information disclosure vulnerability within Microsoft Edge, impacting Microsoft Edge on Windows 10 and Windows Server 2019. This flaw allows for cross-origin request handling issues, potentially leaking sensitive information. Rated Medium (CVSS 4.3), it requires user interaction (UI:R) for an attacker to exploit, but has low impact on confidentiality (C:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB are all clear), or significant community discussion, though it received some media coverage during Microsoft's November 2018 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.