Security Advisory

CVE-2025-56749

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-10-15 00:00:00
Last updated 2025-10-15 17:37:38
Assigner mitre
State PUBLISHED

Description

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.