Fortify
← All intel
NVD/NISTCVE-2025-61305

docuForm Mecury Print Hit by XSS

PublishedMay 11, 2026 at 4:17 PM·low

What happened

A reflected cross-site scripting flaw (CVE-2025-61305) has been disclosed in docuForm's Mecury Managed Print Services v11.11c, specifically in the dfm-menu_firmware.php component. Attackers can craft malicious links that execute arbitrary JavaScript in a victim's browser, potentially hijacking sessions or stealing data from users of the print management system. Administrators should restrict access to the management interface and watch for a vendor patch.

Tags

#xss#docuform#cve-2025-61305#web-vulnerability

Source reference

https://ZeroBreach.de

See how Fortify maps this threat to your compliance posture.

14-day free trial · no credit card · HIPAA, SOC 2, ISO 27001, GDPR

Sign Up →