CVE-2018-1000163
PoC —CVSS 3.0
6.1 medium
EPSS
<1%p50
Published
()
Modified
Description
Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console.
- Vendors
- projectfloodlight
- Products
- floodlight
- Weakness
- CWE-79
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.