PT-2025-26605 · Unknown · Beakon Learning Management System

Published

2025-06-23

·

Updated

2025-10-16

·

CVE-2025-46101

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Beakon Learning Management System SCORM versions prior to 5.4.3
Description: The issue allows a remote attacker to obtain sensitive information. This is achieved via the ks parameter in the "json scorm.php" file, which is vulnerable to SQL Injection.
Recommendations: For versions prior to 5.4.3, update to version 5.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "json scorm.php" file or avoiding the use of the ks parameter in this file until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-46101

Affected Products

Beakon Learning Management System