Junglewise Threat Intelligence

CVE-2025-65416: docuFORM Managed Print Service Client arbitrary file upload in pmupdate.php

CVE-2025-65416 · Severity: info · CVSS 6.3 · Published 2026-05-11

Technologies: docuForm Managed Print Service Client. Vendors: docuForm.

Executive brief

docuFORM Managed Print Service Client, a tool used to manage and monitor corporate printing and scanning infrastructure, contains a security flaw that allows authenticated users to upload unauthorized files. An attacker could use this to upload malicious scripts to the server, potentially leading to a complete system takeover, data theft, or service disruption. A fix was released by the vendor in late 2025.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in docuFORM Managed Print Service Client (also referred to as FSM Client) version 11.11c. The vulnerability is located in the 'pmupdate.php' file, which fails to properly validate file types, extensions, or content during the upload process. An authenticated attacker with network access can exploit this to upload malicious files, such as web shells, to web-accessible directories. Successful exploitation can result in arbitrary code execution under the context of the web server, leading to full system compromise. The vendor has reportedly released a fix as of November 2025.

Affected products

  • docuFORM Managed Print Service Client (FSM Client) 11.11c

Timeline

  • 2025-10: other: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-05-11: disclosed: Public disclosure and CVE assignment

References

Related threats