Impact
The vulnerability resides in the Student Profile Image Upload function of CodeCanyon Rocket LMS. A crafted request containing malicious script can cause the application to embed unsanitized input into a profile page. When a user views that profile, the script executes in their browser context, allowing the attacker to steal client‑side data, hijack sessions, or launch further phishing campaigns.
Affected Systems
Rocket LMS versions 2.0 through 2.2, all builds available from CodeCanyon, are affected. Any installation that uses the default image upload component without additional input filtering is vulnerable. No release beyond 2.2 has been documented as patched.
Risk and Exploitability
The CVSS score of 5.1 classifies the risk as medium. The exploit is remote and unauthenticated and has been publicly disclosed. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation yet. Nevertheless, the combination of remote access, lack of patch, and web‑application exposure makes the flaw a tangible threat to affected users.
OpenCVE Enrichment