Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alex Korobkin

#51026of 53,632
4.3Total CVSS
Vulnerabilities · 1
PT-2014-4923
4.3
2014-04-18
Apple · Cups · CVE-2014-2856
**Name of the Vulnerable Software and Affected Versions** CUPS versions prior to 1.7.2 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the `is path absolute` function. This is due to a flaw in the scheduler/client.c component of the Common Unix Printing System (CUPS). **Recommendations** For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the scheduler/client.c component to minimize the risk of exploitation.