Loading vulnerability details…
CVSS v3.1
2.2
EPSS
0.15%
Published
Oct 15, 2025
Modified
Oct 23, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:NWeaknesses (CWE)
Affected Products (1)
References (1)