Classroomio LMS, Stored Cross-Site Scripting, CVE-2025-65675 (Critical)

Listen to this Post

This stored cross-site scripting (XSS) vulnerability in Classroomio LMS version 0.1.13 arises due to insufficient input sanitization and validation of user-uploaded SVG files used as profile pictures. Authenticated attackers can craft a malicious SVG image containing JavaScript code within elements such as `

Scroll to Top