PT-2025-41934 · Creativeitem · Creativeitem Academy Lms

Published

2025-10-14

·

Updated

2025-10-14

·

CVE-2025-56747

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Creativeitem Academy LMS versions up to and including 5.13
Description A privilege escalation issue exists in the Api instructor controller. Authenticated users without the necessary permissions can access functions intended only for instructors. This allows unauthorized course creation and management. The Api instructor controller lacks proper role validation.
Recommendations Update to a version beyond 5.13.

Exploit

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-56747

Affected Products

Creativeitem Academy Lms