2.2
CVE-2025-56746
- EPSS 0.16%
- Veröffentlicht 15.10.2025 00:00:00
- Zuletzt bearbeitet 23.10.2025 19:42:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Creativeitem ≫ Academy Lms Version <= 5.13
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.05 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 2.2 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
|
CWE-384 Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
https://suryadina.com/academy-lms-session-fixation-1t8v5n3q6h/