Executive brief
A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used by organizations to manage corporate printing and scanning infrastructure. An attacker with basic user access can inject malicious scripts into the system that are then executed in the browsers of other users, including administrators. This could lead to the theft of login sessions, unauthorized access to sensitive print data, or the performance of administrative actions without permission.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the acc-menu_papers.php (also referred to as dfm-menu_papers.php) component of docuForm Mercury Managed Print Services (Mercury Suite) v11.11c. The vulnerability stems from improper neutralization of user-controllable input before it is embedded into dynamically generated web pages. An authenticated attacker can inject a crafted payload into an unfiltered variable, which is then stored by the application and executed in the browser of any user who views the affected page. Successful exploitation can lead to session hijacking via the theft of sensitive session identifiers or unauthorized actions performed on behalf of the victim. A fix was reportedly published by the vendor in November 2025.
Affected products
- docuForm Mercury Managed Print Services (Mercury Suite) 11.11c
Timeline
- 2025-10: disclosed: Vulnerability reported to vendor
- 2025-11: patched: Vendor published a fix
- 2026-05-11: advisory: NVD publication date