CVE-2025-56748 - CERT CVE
ID CVE-2025-56748
Sažetak Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.
Reference
CVSS
Base: 6.4
Impact: 4.7
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 16-10-2025 - 15:28
Objavljeno 15-10-2025 - 15:16