ZeroHour

CVE-2018-1000163

PoC
CVSS 3.0
6.1 medium
EPSS
<1%p50
Published
()
Modified
Description

Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console.

Vendors
projectfloodlight
Products
floodlight
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.