CVE-2026-102290 Details
Description
A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A stored cross-site scripting vulnerability has been identified in CodeCanyon Rocket LMS versions through 2.2. The issue arises in the Student Profile Image Upload component, where the application fails to properly validate or sanitize SVG files before allowing them to be uploaded. This vulnerability can be exploited remotely by authenticated users with student-level access, who can upload an SVG image containing malicious JavaScript. Once the image is uploaded, the JavaScript executes within the application's origin, leading to potential session hijacking, cookie theft, and other attacks against users who view the affected profile image.
To address this vulnerability, restrict profile image uploads to safe raster formats like PNG, JPG/JPEG, and WEBP. If SVG support is necessary, use a trusted SVG sanitizer to clean the files before acceptance. Implement server-side validation of uploaded files, checking MIME types and file signatures rather than relying solely on file extensions. Remove any `<script>` elements and JavaScript event handlers from SVG files before processing. Consider serving uploaded SVGs from a separate origin and applying a Content Security Policy to mitigate script execution risks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1kICrUOCzmXgf2iW1qEX8q9jW_R3twEBb/view?usp=sharing | [email protected] | ExploitPartial Content |
| https://gist.github.com/MuhammadAmmar-Hacker/05f13a39b35ae3dc31d86a5b919b5e2a | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-102290 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/939876 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411167 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411167/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CodeCanyon Rocket LMS | <= 2.2 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion