CVE-2017-7944: XSS
Published Apr 24, 2017
·Updated
XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in pagedbsettings.php.
Affected Software
1 affected component
Xoops Xoops=2.5.8.1
Event History
Apr 24, 2017
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7944?
CVE-2017-7944 is classified as a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2017-7944?
To fix CVE-2017-7944, it is recommended to upgrade to a newer version of XOOPS Core that properly escapes HTML output.
3
What type of vulnerability is CVE-2017-7944?
CVE-2017-7944 is a cross-site scripting (XSS) vulnerability affecting XOOPS Core 2.5.8.1.
4
Where does CVE-2017-7944 appear in XOOPS?
CVE-2017-7944 appears in the page_dbsettings.php file during an Install DB failure error message.
5
Who is affected by CVE-2017-7944?
Users running XOOPS Core version 2.5.8.1 are affected by CVE-2017-7944.