Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
                
            References
                    | Link | Resource | 
|---|---|
| https://suryadina.com/academy-lms-session-fixation-1t8v5n3q6h/ | Exploit Mitigation Third Party Advisory | 
Configurations
                    History
                    23 Oct 2025, 19:42
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://suryadina.com/academy-lms-session-fixation-1t8v5n3q6h/ - Exploit, Mitigation, Third Party Advisory | |
| CPE | cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:* | |
| First Time | Creativeitem Creativeitem academy Lms | 
15 Oct 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-384 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 2.2 | 
15 Oct 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-15 14:15
Updated : 2025-10-23 19:42
NVD link : CVE-2025-56746
Mitre link : CVE-2025-56746
CVE.ORG link : CVE-2025-56746
JSON object : View
Products Affected
                creativeitem
- academy_lms
CWE
                
                    
                        
                        CWE-384
                        
            Session Fixation
