CVE-2025-56746

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/10/2025
Last modified:
23/10/2025

Description

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:* 5.13 (including)


References to Advisories, Solutions, and Tools