VYPR
Medium severity6.4NVD Advisory· Published Oct 15, 2025· Updated Jun 17, 2026

CVE-2025-56748

CVE-2025-56748

Description

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:*range: <=5.13
    • (no CPE)
    • (no CPE)range: <=5.13

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.