CVE-2023-1728: Fernus Learning Management Systems
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection. This issue affects LMS: before 23.04.03.
Affected products
- Fernus Learning Management Systems: before 23.04.03 (fixed in 23.04.03)
Published 2023-04-04. Last modified 2026-06-17.