CVE-2023-53876 - Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings

CVE-2023-53876 - Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings

CVE ID : CVE-2023-53876 Published : Dec. 15, 2025, 9:15 p.m. | 18 minutes ago Description : Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 15, 2025

Source: Telegram CVE Monitor