CVE-2015-1159

EPSS 58.8%
Published: 6/26/2015Modified: 4/28/2026

Description

Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.

Affected packages (1)

References (1)