Cross-site Scripting Vulnerability in Common Unix Printing System (CUPS)
CVE-2014-2856

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
18 April 2014

Summary

A cross-site scripting vulnerability exists in the Common Unix Printing System (CUPS) before version 1.7.2. This flaw allows remote attackers to inject arbitrary web scripts or HTML through the URL path by exploiting the is_path_absolute function, potentially compromising the security of affected systems. Organizations relying on CUPS should upgrade to the latest version to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.