Stored Cross Site Scripting Vulnerability in CiviCRM by CiviCRM LLC
CVE-2025-65187
6.1MEDIUM
What is CVE-2025-65187?
A Stored Cross Site Scripting vulnerability is present in the Accounting Batches field of CiviCRM prior to version 6.7. Authenticated users can exploit this vulnerability by injecting malicious JavaScript, which executes upon viewing the affected page. This can lead to unauthorized actions or exposure of sensitive information, emphasizing the importance of timely updates and security measures.
