The following flaw was found in CUPS: A cross-site scripting bug in the CUPS templating engine allows this bug to be exploited when a user browses the web. This XSS is reachable in the default configuration for Linux instances of CUPS, and allows an attacker to bypass default configuration settings that bind the CUPS scheduler to the 'localhost' or loopback interface. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1159