216.73.217.24

CVE-2025-65923

· Published 03/02/2026 18:16 · Modified 04/02/2026 17:16

Labels: CVE-2025-65923 2026-02-03CVE-2025-65923CWE-79[email protected]

Essential information

Published
03/02/2026 18:16
Modified
04/02/2026 17:16
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and executed whenever the affected record is viewed by a user within the ERPNext web interface. This exposure may allow an attacker to compromise user sessions or perform unauthorized actions under the context of a victim's account.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
erpnext / erpnext cpe:2.3:a:erpnext:erpnext:*:*:*:*:*:*:*:*

References