First published: Thu May 14 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
CUPS libraries | <=2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1159 is classified as a high-severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2015-1159, upgrade to CUPS version 2.0.3 or later, where the vulnerability is addressed.
CVE-2015-1159 affects CUPS versions prior to 2.0.3 running on various operating systems.
Yes, CVE-2015-1159 can allow attackers to execute scripts that may facilitate data theft or unauthorized actions on behalf of users.
CVE-2015-1159 is not specific to any particular browser, as the vulnerability occurs within CUPS and can affect any client accessing it.