CVE-2025-65417
Description
docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
docuFORM Managed Print Service Client 11.11c is vulnerable to reflected XSS via unsanitized input in the login page, allowing script injection.
Vulnerability
Overview A reflected cross-site scripting (XSS) vulnerability exists in the login page of docuFORM Managed Print Service Client version 11.11c. The application fails to properly sanitize user-supplied input before reflecting it in the HTTP response, allowing an attacker to inject arbitrary JavaScript code. This issue is classified as CWE-79 and was reported by security researcher Bastian Recktenwald of ZeroBreach GmbH [2].
Exploitation
Exploitation requires the attacker to craft a malicious URL containing the XSS payload. The victim must click on this link, which can be delivered via phishing or other social engineering methods. No authentication is needed, as the vulnerability exists on the login page. The attacker does not need any special network position; the attack is performed over the network with low complexity [2].
Impact
Successful exploitation allows the attacker to execute scripts in the victim's browser context with the privileges of the application. This can lead to session hijacking by stealing cookies, theft of sensitive data such as credentials or personal information, unauthorized actions performed on behalf of the user, or redirection to malicious sites for malware distribution [2].
Mitigation
The vendor acknowledged the vulnerability and published a fix in November 2025. Users are advised to update to the latest version of docuFORM Managed Print Service Client to remediate the issue. The information about the vulnerability was publicly disclosed in April 2026 [2].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: = 11.11c
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.