Junglewise Threat Intelligence

CVE-2025-61308: docuForm Mercury Managed Print Services XSS in maintenance menu

CVE-2025-61308 · Severity: info · CVSS 7.3 · Published 2026-05-11

Technologies: docuForm Mercury Managed Print Services. Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm Mercury Managed Print Services, a software suite used to manage corporate printing and scanning infrastructure. An attacker with basic user access can inject malicious scripts into the system's maintenance menu. If another user views the affected page, the attacker could steal their login session, access sensitive information, or perform unauthorized actions on their behalf.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the dfm-menu_maintenance.php component of docuForm Mercury Managed Print Services (also known as docuForm FSM Server) version 11.11c. The issue stems from improper neutralization of user-controllable input before it is embedded into dynamically generated web pages. An authenticated attacker with low privileges can inject a crafted payload into an unfiltered variable, which is then stored by the application. When other users navigate to the affected maintenance menu, the malicious script executes in their browser context. This can lead to session hijacking, sensitive data theft, or unauthorized account takeover. A fix was reportedly published by the vendor in November 2025.

Affected products

  • GmbH Mecury Managed Print Services (docuForm) Mercury Managed Print Services (docuForm) 11.11c

Timeline

  • 2025-10: disclosed: Vulnerability reported to the vendor
  • 2025-11: patched: Vendor published a fix for the issue
  • 2026-04: advisory: Information about the vulnerability is published by ZeroBreach
  • 2026-05-11: other: CVE published to NVD

References

Related threats