CVE-2014-2856Cross-site Scripting in Apple Cups

CWE-79Cross-site Scripting10 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
1.0%
top 22.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 18
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianapple/cups< 1.7.2-1+3
NVDapple/cups1.7.1+82

🔴Vulnerability Details

5
GHSA
GHSA-5rr9-vfp7-m4m5: Cross-site scripting (XSS) vulnerability in scheduler/client2022-05-17
OSV
eglibc, glibc regression2016-05-26
OSV
eglibc, glibc vulnerabilities2016-05-25
CVEList
CVE-2014-2856: Cross-site scripting (XSS) vulnerability in scheduler/client2014-04-18
OSV
CVE-2014-2856: Cross-site scripting (XSS) vulnerability in scheduler/client2014-04-18

📋Vendor Advisories

3
Ubuntu
CUPS vulnerability2014-04-24
Red Hat
cups: cross-site scripting flaw fixed in the 1.7.2 release2014-01-30
Debian
CVE-2014-2856: cups - Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Pr...2014

💬Community

1
Bugzilla
CVE-2014-2856 cups: cross-site scripting flaw fixed in the 1.7.2 release2014-04-14
CVE-2014-2856 — Cross-site Scripting in Apple Cups | cvebase