Unrated severityNVD Advisory· Published Dec 15, 2025· Updated Apr 7, 2026
Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings
CVE-2023-53876
Description
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Affected products
2- Range: 6.1
- Range: 6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51702mitreexploit
- www.vulncheck.com/advisories/academy-lms-arbitrary-file-upload-vulnerability-via-profile-settingsmitrethird-party-advisory
- academylms.netmitretechnical-description
News mentions
0No linked articles in our index yet.