Description
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
CraCkEr
References
www.exploit-db.com/exploits/51702
www.exploit-db.com/exploits/51702 (ExploitDB-51702)
academylms.net/ (Academy LMS Product Webpage)
www.vulncheck.com/...load-vulnerability-via-profile-settings (VulnCheck Advisory: Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.