Security Advisory
CVE-2018-1000163
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console.