CVE-2025-56746: Low severity Creativeitem Academy LMS vulnerability
Published Oct 15, 2025
·Updated
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
Affected Software
2 affected components
Creativeitem Academy LMS<=5.13
Creativeitem Academy LMS<=5.13
Event History
Oct 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56746?
CVE-2025-56746 is considered a high severity vulnerability due to its potential for session fixation attacks.
2
How do I fix CVE-2025-56746?
To fix CVE-2025-56746, ensure that the application regenerates session IDs upon successful user authentication.
3
What software is affected by CVE-2025-56746?
CVE-2025-56746 affects Creativeitem Academy LMS versions up to and including 5.13.
4
What type of attack does CVE-2025-56746 enable?
CVE-2025-56746 enables session fixation attacks which can allow attackers to hijack user sessions.
5
Why is it important to address CVE-2025-56746?
Addressing CVE-2025-56746 is critical to prevent potential unauthorized access to user accounts through session hijacking.