Beveiligingsadvies
CVE-2023-53876
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.