CVE-2025-65267

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
Configurations

No configuration.

History

03 Dec 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.0
CWE CWE-79

03 Dec 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 15:15

Updated : 2025-12-03 16:15


NVD link : CVE-2025-65267

Mitre link : CVE-2025-65267

CVE.ORG link : CVE-2025-65267


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')