Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
References
| Link | Resource |
|---|---|
| https://suryadina.com/academy-lms-session-fixation-1t8v5n3q6h/ | Exploit Mitigation Third Party Advisory |
Configurations
History
23 Oct 2025, 19:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:* | |
| First Time |
Creativeitem academy Lms
Creativeitem |
|
| References | () https://suryadina.com/academy-lms-session-fixation-1t8v5n3q6h/ - Exploit, Mitigation, Third Party Advisory |
15 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-384 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.2 |
15 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-15 14:15
Updated : 2025-10-23 19:42
NVD link : CVE-2025-56746
Mitre link : CVE-2025-56746
CVE.ORG link : CVE-2025-56746
JSON object : View
Products Affected
creativeitem
- academy_lms
CWE
CWE-384
Session Fixation
