CVE-2023-53876

MEDIUM

Academy LMS 6.1 - Authenticated Stored Cross-Site Scripting via Profile Avatar Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53876. PoCs published by CraCkEr.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Academy LMS 6.1, allowing attackers to upload malicious SVG files containing stored XSS payloads. The PoC shows how to bypass file extension checks by intercepting and modifying a POST request to upload an SVG file with embedded JavaScript.

Description

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.

Exploits (1)

exploitdb WORKING POC
by CraCkEr · textwebappsphp
https://www.exploit-db.com/exploits/51702

This exploit demonstrates an arbitrary file upload vulnerability in Academy LMS 6.1, allowing attackers to upload malicious SVG files containing stored XSS payloads. The PoC shows how to bypass file extension checks by intercepting and modifying a POST request to upload an SVG file with embedded JavaScript.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Academy LMS 6.1
Auth required
Prerequisites: Valid user credentials · Access to the user dashboard · Ability to intercept and modify HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51702
Product technical-description
https://academylms.net/

Scores

CVSS v3 5.4
EPSS 0.0002
EPSS Percentile 5.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (2)
Creativeitem/Academy LMS 6.1
creativeitem/academy_lms 6.1
Published Dec 15, 2025
Tracked Since Feb 18, 2026