CVE-2025-56748
Last modified
CVE-2025-56748 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Creativeitem | Academy Lms | <= 5.13 |
References
- https://suryadina.com/academy-lms-reset-bruteforce-5q8w2e7t9y/Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-56748?
How severe is CVE-2025-56748?
How do I fix CVE-2025-56748?
Are you affected by CVE-2025-56748?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
