← Back

CVE-2025-56748

nvd nist
Published: Oct 15, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
Exploitability: 1.6 / Impact: 4.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

Affected (1)

1 product
Academy Lms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.13

References (1)

Source: cve@mitre.org
ExploitMitigationThird Party Advisory

Timeline

No history available yet.