PT-2025-42362 · Creativeitem · Creativeitem Academy Lms

Publicado

2025-10-15

·

Atualizado

2025-10-15

·

CVE-2025-56749

CVSS v3.1

9.4

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Creativeitem Academy LMS versions up to and including 6.14
Description The software uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.
Recommendations Update to a version beyond 6.14.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-56749

Produtos afetados

Creativeitem Academy Lms