Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings
Vulnerability Description
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53876
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- CraCkEr
References
More from Creativeitem
View All →Affected Vendor
Creativeitem
View all reports →