Executive brief
A security vulnerability exists in docuForm FSM Server, a software suite used for managing enterprise printing and document workflows. An attacker can exploit this flaw to access sensitive files stored on the server, such as configuration data or system files. This could lead to the exposure of proprietary source code or credentials, potentially allowing for further unauthorized access to the organization's printing infrastructure.
Technical details
A Local File Inclusion (LFI) vulnerability exists in docuForm FSM Server v11.11c within the dfm-menu_report.php component. The root cause is insufficient sanitization of user-supplied input in a file path parameter, specifically categorized as CWE-98. A remote attacker with low-level authentication can exploit this flaw by submitting crafted requests to include local files. Successful exploitation allows the attacker to read sensitive files on the server, including configuration files, source code, and system files. While the NVD summary mentions arbitrary code execution, the primary researcher's technical detail focuses on arbitrary file read capabilities with a CVSS score of 6.5.
Affected products
- docuForm GmbH FSM Server 11.11c
Timeline
- 2026-07-01: disclosed: Initial disclosure by ZeroBreach GmbH via GitHub Gist.
- 2026-07-09: advisory: CVE-2026-51925 published in the NVD dataset.