← Back

CVE-2025-56746

nvd nist
Published: Oct 15, 2025Modified: Jun 17, 2026

JSON object

Loading...
2.2
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Exploitability: 0.8 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.

Affected (1)

1 product
Academy Lms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.13

References (1)

Source: cve@mitre.org
ExploitMitigationThird Party Advisory

Timeline

No history available yet.