CVE-2025-65267

Source
https://cve.org/CVERecord?id=CVE-2025-65267
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65267.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-65267
Published
2025-12-03T00:00:00Z
Modified
2026-08-12T03:51:24Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65267.json"
}
References

Affected packages

Git / github.com/frappe/erpnext

Affected ranges

Type
GIT
Repo
https://github.com/frappe/erpnext
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:frappe:erpnext:15.83.2:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "15.83.2"
        },
        {
            "last_affected": "15.83.2"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

15.*
15.83.2
v15.*
v15.83.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65267.json"

Git / github.com/frappe/frappe

Affected ranges

Type
GIT
Repo
https://github.com/frappe/frappe
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:frappe:frappe:15.86.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "15.86.0"
        },
        {
            "last_affected": "15.86.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

15.*
15.86.0
v15.*
v15.86.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65267.json"