CVE-2023-53876 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. At…
Medium CVSS: 5.1

CVE-2023-53876

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Vendor
Creativeitem
Product
Academy Lms
CWE
CWE-434
Yayın Tarihi
2025-12-15 21:15:50
Güncelleme
2025-12-18 22:35:48
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar