CVE-2025-65267
Last modified
CVE-2025-65267 is a critical-severity vulnerability rated 9/10 on the CVSS scale. In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Frappe | Erpnext | 15.83.2 |
| Frappe | Frappe | 15.86.0 |
References
- https://github.com/PhDg1410/CVE/tree/main/CVE-2025-65267Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-65267?
How severe is CVE-2025-65267?
How do I fix CVE-2025-65267?
Are you affected by CVE-2025-65267?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
