A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Civicrm
Civicrm civicrm |
|
| Vendors & Products |
Civicrm
Civicrm civicrm |
Tue, 02 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-02T00:00:00.000Z
Updated: 2025-12-02T19:30:37.641Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65187
Updated: 2025-12-02T19:30:33.787Z
Status : Awaiting Analysis
Published: 2025-12-02T16:15:56.157
Modified: 2025-12-02T20:15:52.670
Link: CVE-2025-65187
No data.