CVE-2025-56746
15.10.2025, 14:15
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.Enginsight
| Vendor | Product | Version |
|---|---|---|
| creativeitem | academy_lms | 𝑥 ≤ 5.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration