Junglewise Threat Intelligence

CVE-2025-61305: docuForm Mercury Managed Print Services XSS in dfm-menu_firmware.php

CVE-2025-61305 · Severity: info · CVSS 7.3 · Published 2026-05-11

Technologies: docuForm Mercury Managed Print Services. Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used for managing corporate printing and scanning infrastructure. An attacker can inject malicious scripts into the system's firmware management component, which could allow them to steal user session information or take over accounts. This could lead to unauthorized access to print management functions and sensitive document workflows.

Technical details

A cross-site scripting (XSS) vulnerability exists in the dfm-menu_firmware.php component of docuForm Mercury Managed Print Services (also referred to as FSM Server) version 11.11c. The flaw stems from improper neutralization of user-controllable input before it is embedded into dynamically generated web pages. While some sources describe it as reflected, the researcher's detailed advisory indicates it is a stored XSS vulnerability where an authenticated attacker can inject a crafted payload into a variable that is subsequently saved and rendered unsafely for other users. Successful exploitation allows for the execution of arbitrary JavaScript, potentially leading to session hijacking (theft of session identifiers), unauthorized account takeover, or modification of application content. A fix was reportedly published by the vendor in November 2025.

Affected products

  • GmbH Mecury Managed Print Services (docuForm) Mercury Managed Print Services (docuForm) 11.11c

Timeline

  • 2025-10: disclosed: Vulnerability reported to the vendor
  • 2025-11: patched: Vendor published a fix for the issue
  • 2026-04: advisory: Researcher published vulnerability details
  • 2026-05-11: disclosed: CVE published to NVD

References

Related threats