CVE-2023-53876
15.12.2025, 21:15
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.Enginsight
| Vendor | Product | Version |
|---|---|---|
| creativeitem | academy_lms | 6.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration