CVE-2025-65267

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:frappe:erpnext:15.83.2:*:*:*:*:*:*:*
cpe:2.3:a:frappe:frappe:15.86.0:*:*:*:*:*:*:*

History

05 Dec 2025, 18:35

Type Values Removed Values Added
References () https://github.com/PhDg1410/CVE/tree/main/CVE-2025-65267 - () https://github.com/PhDg1410/CVE/tree/main/CVE-2025-65267 - Third Party Advisory
References () https://github.com/frappe/erpnext - () https://github.com/frappe/erpnext - Product
References () https://github.com/frappe/frappe - () https://github.com/frappe/frappe - Product
First Time Frappe erpnext
Frappe frappe
Frappe
CPE cpe:2.3:a:frappe:frappe:15.86.0:*:*:*:*:*:*:*
cpe:2.3:a:frappe:erpnext:15.83.2:*:*:*:*:*:*:*

03 Dec 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.0
CWE CWE-79

03 Dec 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 15:15

Updated : 2025-12-05 18:35


NVD link : CVE-2025-65267

Mitre link : CVE-2025-65267

CVE.ORG link : CVE-2025-65267


JSON object : View

Products Affected

frappe

  • frappe
  • erpnext
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')