Executive brief
A security vulnerability exists in docuFORM Mercury Managed Print Services, a platform used to manage corporate printing and scanning infrastructure. An attacker can inject malicious scripts into the system that are then executed in the browsers of other users, such as administrators. This could lead to the theft of login sessions, unauthorized access to sensitive print data, or the performance of administrative actions without permission.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the acc-menu_pricess.php component of docuFORM Mercury Managed Print Services (also referred to as docuForm FSM Server) version 11.11c. The flaw stems from improper neutralization of user-controllable input before it is stored and subsequently embedded into dynamically generated web pages. An authenticated attacker with low privileges can inject a crafted payload into an unfiltered variable. When other users (including administrators) view the affected page, the malicious script executes in their browser context. This can be leveraged to steal session identifiers, perform unauthorized actions, or modify application content. A fix was reportedly published by the vendor in November 2025.
Affected products
- GmbH Mecury Managed Print Services (docuForm) Mercury Managed Print Services (docuForm) 11.11c
Timeline
- 2025-10: disclosed: Vulnerability reported to the vendor
- 2025-11: patched: Vendor published a fix for the issue
- 2026-04: advisory: Public disclosure by ZeroBreach GmbH
- 2026-05-11: other: CVE published to NVD