Stored Cross-Site Scripting Vulnerability in ERPNext by Frappe
CVE-2025-65923
5.4MEDIUM
What is CVE-2025-65923?
A vulnerability exists in ERPNext up to version 15.88.1 related to stored cross-site scripting (XSS) through the CSV import feature. When the 'Update Existing Records' option is used, an attacker can inject malicious JavaScript code into CSV fields. This code becomes stored in the ERPNext database and is executed when the affected record is accessed via the web interface. As a result, attackers could potentially compromise user sessions or conduct unauthorized actions by exploiting the trust users place in the application.
