ZeroHour

CVE-2025-56746

PoC
CVSS 3.1
2.2 low
EPSS
<1%p5
Published
()
Modified
Description

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.

Vendors
creativeitem
Products
academy lms
Weakness
CWE-384
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.