Sceawere
Vulnerability Detail
CVE-2026-102290UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Rocket LMS Profile XSS Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 2h ago
- Vendor
- CodeCanyon
- Product
- Rocket LMS
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-09-29T05:16:59.200Z",
"pubdate": "2026-09-29T05:16:59.200Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the Student Profile Image Upload component of Rocket LMS up to version 2.2.\nThis vulnerability allows remote attackers to inject malicious scripts into the application, which are then executed within the browser session of a victim.\nThe flaw stems from insufficient sanitization or validation of user-supplied data during the profile image upload process.\nThe risk implication is critical, as successful exploitation permits unauthorized script execution, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of authenticated users.\nThe attack is remotely exploitable and does not require complex setup, as the exploit has been publicly disclosed.\nThe vendor remains unresponsive to disclosure attempts, necessitating proactive defensive measures by administrators to secure affected installations.",
"technicalDetails": "The vulnerability is located in the Student Profile Image Upload functionality of Rocket LMS, affecting all versions up to and including 2.2.\nThe root cause is an improper neutralization of input during the file upload or profile metadata handling process, specifically where filenames or associated metadata are insufficiently validated before being reflected in the Document Object Model (DOM).\nAn attacker can exploit this by crafting a malicious payload within the metadata of an image file or by manipulating the upload request parameters to inject Cross-Site Scripting (XSS) vectors.\nWhen a user or administrator views the profile page where the manipulated image metadata is rendered, the web application inadvertently executes the injected script within the context of the user's browser session.\nThe attack flow follows a predictable pattern: first, the attacker identifies the file upload endpoint associated with the student profile. Second, the attacker uploads a file with a malicious script embedded in a field that the application fails to sanitize, such as the image filename or hidden attributes processed during the upload handshake.\nOnce the file is uploaded, the malicious payload is stored on the server. When the profile page is subsequently requested by a target user, the server reflects the unsanitized input into the HTML response.\nThe victim's browser interprets the injected script as legitimate code originating from the trusted domain, granting the attacker the ability to execute arbitrary JavaScript.\nPost-exploitation impact includes the potential for session token theft via document.cookie access, redirection to malicious external sites, unauthorized modification of the user interface (defacement), or the triggering of background requests to perform administrative actions if the victim holds higher privileges.\nBecause the payload is stored within the application's persistent storage, this qualifies as a Stored (Persistent) XSS vulnerability. Given the remote accessibility of the upload component and the absence of robust input filtering or Output Encoding, the application remains highly susceptible to compromise."
}