docuForm Mercury Managed Print Services Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the dfm-menu_coveragealerts.php component of docuForm Mercury Managed Print Services version 11.11c. This vulnerability allows attackers to execute arbitrary JavaScript in the context of a user's browser by injecting a crafted payload into an unfiltered variable.

Impact

Exploitation of this vulnerability allows for the injection and execution of malicious scripts in the context of the user's session, potentially leading to the theft of sensitive information such as session identifiers or personal user data. This could result in unauthorized account access or the execution of unintended actions on behalf of the user.

Added: May 11, 2026, 4:57 PM
Updated: May 11, 2026, 4:57 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
0.0
relevance
8.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.