vendor:
Academy LMS
by:
CraCkEr
7.5
CVSS
HIGH
Arbitrary File Upload
79, 74, 707
CWE
Product Name: Academy LMS
Affected Version From: 6.1
Affected Version To: 6.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro
2023
Academy LMS 6.1 – Arbitrary File Upload
Allows Attacker to upload malicious files onto the server, such as Stored XSS
Mitigation:
Implement proper file upload validation and sanitization. Limit file types and restrict file permissions.