CVE-2025-56749
15.10.2025, 15:16
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.Enginsight
| Vendor | Product | Version |
|---|---|---|
| creativeitem | academy_lms | 𝑥 ≤ 6.14 |
𝑥
= Vulnerable software versions