Advisories

Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings

Go Back
severity
medium
date
Affecting
  • Academy LMS 6.1

CWE
  • CWE-434 Unrestricted Upload of File with Dangerous Type
CVSS
5.1
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Credit
CraCkEr
Description
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.