Junglewise Threat Intelligence

CVE-2025-61310: docuForm Mercury Managed Print Services Stored XSS in acc-menu_billings.php

CVE-2025-61310 · Severity: info · CVSS 7.3 · Published 2026-05-11

Technologies: docuForm Mercury Managed Print Services. Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used to manage corporate printing and scanning infrastructure. An attacker with basic user access can inject malicious scripts into the system's billing component. If another user views the affected page, the script could steal their login session or personal information, potentially allowing the attacker to take over their account or perform unauthorized actions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the acc-menu_billings.php component of docuForm Mercury Managed Print Services (also referred to as FSM Server) version 11.11c. The issue stems from improper neutralization of user-controllable input before it is embedded into dynamically generated web pages. An authenticated attacker can inject a crafted payload into an unfiltered variable, which is then stored by the application. When other users (such as administrators) navigate to the affected billing menu, the malicious script executes in their browser context. This can lead to session hijacking, unauthorized modification of application data, or account takeover. A fix was reportedly published by the vendor in November 2025.

Affected products

  • docuForm Mercury Managed Print Services (Mercury Suite) 11.11c

Timeline

  • 2025-10: disclosed: Vulnerability reported to the vendor
  • 2025-11: patched: Vendor published a fix for the issue
  • 2026-05-11: advisory: CVE published to NVD

References

Related threats