PT-2025-41934 · Creativeitem · Creativeitem Academy Lms

CVE-2025-56747

·

Published

2025-10-14

·

Updated

2025-10-14

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Creativeitem Academy LMS versions up to and including 5.13
Description A privilege escalation issue exists in the Api instructor controller. Authenticated users without the necessary permissions can access functions intended only for instructors. This allows unauthorized course creation and management. The Api instructor controller lacks proper role validation.
Recommendations Update to a version beyond 5.13.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-56747

Affected Products

Creativeitem Academy Lms