CVE-2023-53876
Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
| CWE | CWE-434 |
| Vendor | creativeitem |
| Product | academy lms |
| Published | Dec 15, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for creativeitem academy lms
Be the first to know when new unknown vulnerabilities affecting creativeitem academy lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Creativeitem / Academy LMS
6.1
References
Credits
CraCkEr