CVE-2025-65187: XSS
A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65187?
CVE-2025-65187 is classified as a stored cross-site scripting (XSS) vulnerability, which poses a significant security risk.
How do I fix CVE-2025-65187?
To fix CVE-2025-65187, upgrade CiviCRM to version 6.7 or later.
Who is affected by CVE-2025-65187?
Authenticated users of CiviCRM versions prior to 6.7 are affected by CVE-2025-65187.
What is stored cross-site scripting in the context of CVE-2025-65187?
Stored cross-site scripting in CVE-2025-65187 allows an attacker to inject malicious JavaScript into the Accounting Batches field, executing it whenever the page is viewed.
How does CVE-2025-65187 impact CiviCRM users?
CVE-2025-65187 can lead to unauthorized script execution, potentially compromising user data and session security.