{"id":"CVE-2018-1000998","details":"FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim must load specially crafted url. This vulnerability appears to have been fixed in 3.x.","modified":"2026-03-14T09:25:47.311717Z","published":"2019-02-04T21:29:00.300Z","references":[{"type":"EVIDENCE","url":"https://www.kvakil.me/posts/cvsweb/"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000998.json","unresolved_ranges":[{"events":[{"introduced":"2.0.4"},{"last_affected":"2.0.6"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}