Security Advisory

CVE-2023-53876

5.4
MEDIUM

Vulnerability Description

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Published Date December 15, 2025
Official Source NIST NVD Advisory