CVE-2018-1000163: Projectfloodlight Floodlight

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console.

Affected products

Published 2018-04-18. Last modified 2026-06-17.