Junglewise Threat Intelligence

CVE-2025-61309: docuForm Mercury Managed Print Services XSS in dfm-menu_departments.php

CVE-2025-61309 · Severity: info · CVSS 7.3 · Published 2026-05-11

Technologies: docuForm Mercury Managed Print Services. Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used for managing corporate printing and scanning infrastructure. An attacker can inject malicious scripts into the system that are then executed in the browsers of other users, such as administrators. This could lead to the theft of login sessions, unauthorized access to sensitive print data, or the ability to perform actions on behalf of other users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the dfm-menu_departments.php component of docuForm Mercury Managed Print Services (also referred to as FSM Server) version 11.11c. The application fails to properly neutralize user-controllable input before embedding it into dynamically generated web pages. An authenticated attacker with low privileges can inject a crafted payload into a variable that is subsequently stored and rendered unsafely in the browsers of other users. Successful exploitation can lead to session hijacking, sensitive information disclosure, or unauthorized administrative actions. While some initial reports categorized this as reflected XSS, the researcher's detailed disclosure confirms it is a stored vulnerability. A fix was reportedly published by the vendor in November 2025.

Affected products

  • docuForm Mercury Managed Print Services (docuForm) 11.11c

Timeline

  • 2025-10: other: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-05-11: advisory: Public disclosure and CVE assignment

References

Related threats