{"api_version":"1","generated_at":"2026-07-23T10:03:28+00:00","cve":"CVE-2018-1000163","urls":{"html":"https://cve.report/CVE-2018-1000163","api":"https://cve.report/api/cve/CVE-2018-1000163.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-1000163","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000163"},"summary":{"title":"CVE-2018-1000163","description":"Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-04-18 19:29:00","updated_at":"2018-05-21 16:14:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://xiaofen9.github.io/blog/floodlight-rce/","name":"https://xiaofen9.github.io/blog/floodlight-rce/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Floodlight Remote Command Execution | Feng's Blog","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-1000163","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000163","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"1000163","vulnerable":"1","versionEndIncluding":"1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"projectfloodlight","cpe5":"floodlight","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","DATE_ASSIGNED":"2018-04-06T14:09:26.585891","DATE_REQUESTED":"2018-03-30T10:21:08","ID":"CVE-2018-1000163","REQUESTER":"f3i@t00ls.net","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://xiaofen9.github.io/blog/floodlight-rce/","refsource":"MISC","url":"https://xiaofen9.github.io/blog/floodlight-rce/"}]}},"nvd":{"publishedDate":"2018-04-18 19:29:00","lastModifiedDate":"2018-05-21 16:14:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:projectfloodlight:floodlight:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"1000163","Ordinal":"126631","Title":"CVE-2018-1000163","CVE":"CVE-2018-1000163","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"1000163","Ordinal":"1","NoteData":"Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"1000163","Ordinal":"2","NoteData":"2018-04-18","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"1000163","Ordinal":"3","NoteData":"2018-04-18","Type":"Other","Title":"Modified"}]}}}