GmbH Mecury Managed Print Services Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the acc-menu_pricess.php component of GmbH Mecury Managed Print Services (docuForm) version 11.11c. This vulnerability allows attackers to execute arbitrary JavaScript in the context of a user's browser by injecting a crafted payload into an unfiltered variable.

Impact

Exploitation of this vulnerability allows for the injection and execution of malicious scripts in the affected user's browser, potentially leading to the theft of session identifiers or personal information, unauthorized account takeover, or unintended actions performed on behalf of the victim.

Added: May 11, 2026, 4:53 PM
Updated: May 11, 2026, 4:53 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
0.0
relevance
8.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.