CVE-2025-65267

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:frappe:erpnext:15.83.2:*:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:15.86.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-03 15:15

Updated : 2025-12-05 18:35


NVD link : CVE-2025-65267

Mitre link : CVE-2025-65267

CVE.ORG link : CVE-2025-65267


JSON object : View

Products Affected

frappe

  • erpnext
  • frappe
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')