A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 02 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-02T19:30:37.641Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65187
Updated: 2025-12-02T19:30:33.787Z
Status : Awaiting Analysis
Published: 2025-12-02T16:15:56.157
Modified: 2025-12-02T20:15:52.670
Link: CVE-2025-65187
No data.
OpenCVE Enrichment
No data.