CVE-2023-53876: Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53876?
CVE-2023-53876 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2023-53876?
To fix CVE-2023-53876, ensure that file uploads are properly validated and sanitized to prevent malicious SVG file uploads.
Who is affected by CVE-2023-53876?
CVE-2023-53876 affects users of Academy LMS version 6.1 where authenticated users can exploit the file upload feature.
What type of attack can CVE-2023-53876 lead to?
CVE-2023-53876 can lead to stored cross-site scripting attacks, allowing attackers to execute malicious scripts in user sessions.
Is CVE-2023-53876 exploitability easy?
Yes, CVE-2023-53876 can be easily exploited by authenticated users with access to the profile avatar upload feature.