Hello Debian Printing Team,
version 2.4.2 of cups contains an XSS vulnerability that was fixed in commit
988ddfd[0] and published in release v2.4.8[1].
Exploitation is trivial:
"https://localhost:631/admin?DEBUG_LOGGING=onfocus=alert(1) autofocus="
However, no CVE was assigned, so no one backported this patch to
2.4.2-3+deb12u8.
The vulnerability was detected by Tenable, which performs various fuzzing
scans.
*** Reporter, please consider answering these questions, where appropriate ***
* What led up to the situation?
* What exactly did you do (or not do) that was effective (or
ineffective)?
* What was the outcome of this action?
* What outcome did you expect instead?
*** End of the template - remove these template lines ***
[0]
https://github.com/OpenPrinting/cups/commit/988ddfd9e66affdb4ed8714c30de96fb304ef4cb
[1] https://github.com/OpenPrinting/cups/releases/tag/v2.4.8