Medium severity5.4NVD Advisory· Published Dec 15, 2025· Updated Jun 17, 2026
CVE-2023-53876
CVE-2023-53876
Description
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <6.1
6.1+ 1 more
- (no CPE)range: 6.1
- cpe:2.3:a:creativeitem:academy_lms:6.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51702nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/academy-lms-arbitrary-file-upload-vulnerability-via-profile-settingsnvdThird Party Advisory
- academylms.netnvdProduct
News mentions
0No linked articles in our index yet.