Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:creativeitem:academy_lms:6.1:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Creativeitem
Creativeitem academy Lms |
|
| Vendors & Products |
Creativeitem
Creativeitem academy Lms |
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code. | |
| Title | Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:07:02.883Z
Reserved: 2025-12-13T14:25:04.999Z
Link: CVE-2023-53876
Updated: 2025-12-15T21:40:40.606Z
Status : Analyzed
Published: 2025-12-15T21:15:50.280
Modified: 2025-12-18T22:35:48.790
Link: CVE-2023-53876
No data.
OpenCVE Enrichment
Updated: 2025-12-16T17:11:25Z