Low severity2.2NVD Advisory· Published Oct 15, 2025· Updated Jun 17, 2026
CVE-2025-56746
CVE-2025-56746
Description
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:*range: <=5.13
- (no CPE)
- (no CPE)range: <=5.13
Patches
Vulnerability mechanics
References
1- suryadina.com/academy-lms-session-fixation-1t8v5n3q6h/nvdExploitMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.