XOOPS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7944 - Vulnerability Database

XOOPS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7944

Medium
Reference: CVE-2017-7944
Title: XOOPS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.