CVE-2025-56749

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.
References
Link Resource
https://suryadina.com/academy-lms-jwt-secret-7k9m2x4p8q/ Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-15 15:16

Updated : 2025-10-21 19:24


NVD link : CVE-2025-56749

Mitre link : CVE-2025-56749

CVE.ORG link : CVE-2025-56749


JSON object : View

Products Affected

creativeitem

  • academy_lms
CWE
CWE-798

Use of Hard-coded Credentials