
Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images. Discovered by - Rivek Raj Tamang (RivuDon), Sikkim, India.
Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images. Discovered by - Rivek Raj Tamang (RivuDon), Sikkim, India.
Affected Product: ClassroomIO
Stored Cross Site Scripting
A Stored Cross-Site Scripting (XSS) vulnerability exists in Classroomio LMS version 0.1.13, where the application fails to sanitize course cover image uploads. An authenticated attacker can upload a malicious SVG file containing embedded JavaScript, which is then stored and executed whenever the course cover image is viewed. Because the payload is executed from a trusted domain, this flaw can lead to session hijacking, account takeover, redirection attacks, or further exploitation within the platform.
Log in and go to created course or create one
Click on landing page
Click on Header > replace image cover
Select the xss svg file and click on upload
Wait for it to save, refresh the page
Right click on the course cover image and open on a new tab
Note the stored xss being popped.

This vulnerability was discovered and responsibly reported by:
Rivek Raj Tamang (RivuDon) from Sikkim, India