CVE-2023-53876
Severity CVSS v4.0:
MEDIUM
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
15/12/2025
Last modified:
15/12/2025
Description
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM



