Junglewise Threat Intelligence

CVE-2025-65417: docuFORM Managed Print Service Client reflected XSS in login page

CVE-2025-65417 · Severity: info · CVSS 8.1 · Published 2026-05-11

Technologies: docuForm Managed Print Service Client. Vendors: docuForm.

Executive brief

docuFORM Managed Print Service Client, a tool used to manage corporate printing and scanning infrastructure, is vulnerable to a security flaw on its login page. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login credentials, session hijacking, or unauthorized access to sensitive print management data.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the login page of docuFORM Managed Print Service Client (also referred to as FSM Client) version 11.11c. The application fails to properly sanitize and encode user-supplied input before reflecting it in the HTTP response. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to steal session cookies (CWE-79). The vendor has reportedly released a fix as of November 2025.

Affected products

  • docuFORM Managed Print Service Client (FSM Client) 11.11c

Timeline

  • 2025-10: other: Vulnerability reported to vendor
  • 2025-11: patched: Vendor published a fix
  • 2026-05-11: advisory: Public disclosure and CVE assignment

References

Related threats