Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-53876 1 Creativeitem 1 Academy Lms 2026-04-07 5.4 Medium
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
CVE-2023-4119 1 Creativeitem 1 Academy Lms 2024-11-21 4.3 Medium
A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the argument query/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-235966 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.