Junglewise Threat Intelligence

CVE-2025-61311: docuForm Mercury Managed Print Services XSS in dfm-menu_alerts.php

CVE-2025-61311 · Severity: info · CVSS 7.3 · Published 2026-05-11

Technologies: docuForm Mercury Managed Print Services. Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used to manage corporate printing and scanning infrastructure. An attacker with basic user access can inject malicious scripts into the system's alert management component. If another user or administrator views the affected page, the script could allow the attacker to steal session information, take over accounts, or perform unauthorized actions on the victim's behalf.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the dfm-menu_alerts.php component of docuForm Mercury FSM Server (Managed Print Services) version 11.11c. The root cause is improper neutralization of user-controllable input before it is embedded into dynamically generated web pages. An authenticated attacker with low privileges can inject a crafted payload into a variable that is subsequently stored by the application. When other users, including administrators, view the alerts menu, the malicious script executes in their browser context. This can lead to session hijacking via cookie theft or unauthorized modification of application data. A fix was reportedly published by the vendor in November 2025.

Affected products

  • docuForm Mercury Managed Print Services (FSM Server) 11.11c

Timeline

  • 2025-10: disclosed: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-05-11: advisory: CVE published to NVD

References

Related threats