GmbH docuFORM Managed Print Services Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in the acc-menu_billings.php component of GmbH docuFORM Managed Print Services version 11.11c. This vulnerability allows attackers to execute arbitrary JavaScript in the context of a user's browser by injecting a crafted payload into an unfiltered variable.
Impact
Exploitation of this vulnerability allows for the injection of malicious scripts that are executed in the context of other users' sessions, potentially leading to the theft of sensitive session information or personal user data, unauthorized account access, or unintended actions being performed on behalf of the victim.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
