Executive brief
A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used by organizations to monitor and manage corporate printing and scanning infrastructure. An attacker with basic user access can inject malicious scripts into the system's management interface. If another user views the affected page, the attacker could steal login sessions, perform unauthorized actions on their behalf, or access sensitive personal information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the dfm-menu_markeralerts.php component of docuForm Mercury Managed Print Services (also known as docuForm FSM Server) version 11.11c. The root cause is improper neutralization of user-controllable input before it is embedded into dynamically generated web pages. An authenticated attacker can inject a crafted payload into an unfiltered variable, which is then stored by the application. When other users navigate to the affected component, the malicious script executes in their browser context. This can lead to session hijacking, unauthorized account takeover, or modification of application data. A fix was reportedly published by the vendor in November 2025.
Affected products
- docuForm Mercury Managed Print Services (Mercury Suite) 11.11c
Timeline
- 2025-10: disclosed: Vulnerability reported to vendor
- 2025-11: patched: Vendor published a fix
- 2026-05-11: advisory: CVE published to NVD