Description
A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-29
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑site scripting via student profile image upload
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Student Profile Image Upload function of CodeCanyon Rocket LMS. A crafted request containing malicious script can cause the application to embed unsanitized input into a profile page. When a user views that profile, the script executes in their browser context, allowing the attacker to steal client‑side data, hijack sessions, or launch further phishing campaigns.

Affected Systems

Rocket LMS versions 2.0 through 2.2, all builds available from CodeCanyon, are affected. Any installation that uses the default image upload component without additional input filtering is vulnerable. No release beyond 2.2 has been documented as patched.

Risk and Exploitability

The CVSS score of 5.1 classifies the risk as medium. The exploit is remote and unauthenticated and has been publicly disclosed. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation yet. Nevertheless, the combination of remote access, lack of patch, and web‑application exposure makes the flaw a tangible threat to affected users.

Generated by OpenCVE AI on September 29, 2026 at 06:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Rocket LMS to the latest released version from CodeCanyon, which removes the insecure image‑upload handling.
  • If a patch is not yet available, disable the public student profile image upload feature or restrict the upload to a whitelist of safe file types and verify the MIME type on the server side.
  • Implement server‑side output encoding or sanitization of image metadata and any user‑supplied data before rendering it in the profile page, ensuring no embedded HTML or JavaScript can survive.

Generated by OpenCVE AI on September 29, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title CodeCanyon Rocket LMS Student Profile Image Upload cross site scripting
First Time appeared Codecanyon
Codecanyon rocket Lms
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:codecanyon:rocket_lms:*:*:*:*:*:*:*:*
Vendors & Products Codecanyon
Codecanyon rocket Lms
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Codecanyon Rocket Lms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-29T04:45:14.287Z

Reserved: 2026-09-28T20:13:03.559Z

Link: CVE-2026-102290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T05:16:59.200

Modified: 2026-09-29T05:16:59.200

Link: CVE-2026-102290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T06:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')