CVE-2023-53876

Severity CVSS v4.0:
MEDIUM
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
15/12/2025
Last modified:
15/12/2025

Description

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.