Security Advisory

CVE-2025-61305

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-11 00:00:00
Last updated 2026-05-11 18:44:18
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_firmware.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.