Junglewise Threat Intelligence

CVE-2025-61314: docuForm Mercury MPS stored XSS in dfm-menu_orderopt.php

CVE-2025-61314 · Severity: info · CVSS 7.3 · Published 2026-05-11

Vendors: docuForm.

Executive brief

A security vulnerability exists in docuForm Mercury Managed Print Services, a platform used by organizations to manage and monitor corporate printing and scanning infrastructure. An attacker with basic user access can inject malicious scripts into the system's management interface. If another user, such as an administrator, views the affected page, the script could allow the attacker to steal session information, take over accounts, or perform unauthorized actions on the victim's behalf.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the docuForm Mercury MPS (also referred to as FSM Server) within the 'dfm-menu_orderopt.php' component. The flaw stems from improper neutralization of user-controllable input before it is embedded into dynamically generated web pages. An authenticated attacker with low privileges can inject a crafted payload into an unfiltered variable. When other users (including administrators) navigate to the affected component, the malicious script executes in their browser context. This can lead to the theft of sensitive session identifiers, unauthorized account takeover, or modification of application data. A fix was reportedly published by the vendor in November 2025.

Affected products

  • docuForm (GmbH) Mercury Managed Print Services (MPS) / FSM Server 11.11c

Timeline

  • 2025-10: disclosed: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-04: advisory: Public disclosure by ZeroBreach GmbH
  • 2026-05-11: other: CVE published to NVD dataset

References