In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:frappe:erpnext:15.83.2:*:*:*:*:*:*:* cpe:2.3:a:frappe:frappe:15.86.0:*:*:*:*:*:*:* |
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frappe
Frappe erpnext Frappe frappe |
|
| Vendors & Products |
Frappe
Frappe erpnext Frappe frappe |
Wed, 03 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 03 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-03T00:00:00.000Z
Updated: 2025-12-03T15:13:30.219Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65267
Updated: 2025-12-03T15:12:58.155Z
Status : Analyzed
Published: 2025-12-03T15:15:55.103
Modified: 2025-12-05T18:35:19.883
Link: CVE-2025-65267
No data.