Junglewise Threat Intelligence

CVE-2025-65415: docuFORM Managed Print Service Client session fixation in login page

CVE-2025-65415 · Severity: info · CVSS 5.4 · Published 2026-05-11

Technologies: docuForm Managed Print Service Client. Vendors: docuForm.

Executive brief

docuFORM Managed Print Service Client is a tool used to manage and monitor corporate printing and scanning infrastructure. A security flaw in the login process allows an attacker to potentially hijack a user's session by fixing their session identifier before they log in. If successful, an attacker could gain unauthorized access to the application, potentially compromising print management operations and sensitive document workflows.

Technical details

The docuFORM Managed Print Service Client (also referred to as FSM Client) version 11.11c is vulnerable to session fixation (CWE-384). The application fails to generate a new session identifier after a user successfully authenticates. An attacker can exploit this by pre-setting a session ID and inducing a victim to log in using that specific ID (typically via a crafted link or social engineering). Once the victim authenticates, the attacker can use the known session ID to hijack the authenticated session. The vendor has reportedly released a fix for this issue.

Affected products

  • docuFORM Managed Print Service Client (FSM Client) 11.11c

Timeline

  • 2025-10: other: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-05-11: disclosed: Public disclosure and CVE assignment

References

Related threats