Vulnerability Description
Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_bundles/search/query endpoint. These vulnerabilities are distinct from the patch for CVE-2023-4119, which only fixed XSS in query and sort_by parameters to the /academy/home/courses endpoint.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Creativeitem | Academy Lms | 7.0 |
Related Weaknesses (CWE)
References
- https://codecanyon.net/item/academy-course-based-learning-management-system/2270Product
- https://creativeitem.com/products/academy-learning-management-system/Broken Link
- https://github.com/cod3rLucas/security-advisories/blob/main/CVE-2025-71179.mdExploitThird Party Advisory
- https://www.exploit-db.com/exploits/51654ExploitThird Party Advisory
FAQ
What is CVE-2025-71179?
CVE-2025-71179 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_bund...
How severe is CVE-2025-71179?
CVE-2025-71179 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71179?
Check the references section above for vendor advisories and patch information. Affected products include: Creativeitem Academy Lms.