Junglewise Threat Intelligence

CVE-2025-61306: docuForm Mercury Managed Print Services XSS in coverage alerts

CVE-2025-61306 · Severity: info · CVSS 7.3 · Published 2026-05-11

Technologies: docuForm Mercury Managed Print Services. Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used to manage corporate printing and scanning infrastructure. An attacker with basic user access can inject malicious scripts into the system's management interface. If another user views the affected page, the script could steal their session information, potentially allowing the attacker to take over their account or perform unauthorized actions within the print management system.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the docuForm Mercury Managed Print Services (FSM Server) within the dfm-menu_coveragealerts.php component. The issue stems from improper neutralization of user-controllable input before it is stored and subsequently embedded into dynamically generated web pages. An authenticated attacker can inject a crafted payload into an unfiltered variable, which is then executed in the browser of any user who views the coverage alerts menu. This can lead to session hijacking via cookie theft or unauthorized actions performed on behalf of the victim. While some sources label this as reflected, the primary researcher's technical detail confirms it is a stored XSS. A fix was reportedly published by the vendor in November 2025.

Affected products

  • docuForm (GmbH Mecury) Mercury Managed Print Services (Mercury Suite) 11.11c

Timeline

  • 2025-10: disclosed: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-05-11: advisory: Public disclosure and CVE assignment

References

Related threats