CVE-2025-56746
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/10/2025
Last modified:
23/10/2025
Description
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
Impact
Base Score 3.x
2.20
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:* | 5.13 (including) |
To consult the complete list of CPE names with products and versions, see this page



