Back to search
CVE-2023-53876
Published: Dec 15, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
| Vendor | Product | Versions |
|---|---|---|
Creativeitem | Academy LMS | affected 6.1 |
Weaknesses (CWE)
References
ExploitDB-51702
exploit
Academy LMS Product Webpage
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now