2.2
/ 10
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Description
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
Basic Information
ID
CVE-2025-56746
Source
mitre
Published
Oct 15, 2025 at 00:00
Modified
Oct 15, 2025 at 15:36
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a