Reflected Cross-Site Scripting Vulnerability in Creativeitem Academy LMS
CVE-2025-71179
6.1MEDIUM
What is CVE-2025-71179?
Creativeitem Academy LMS version 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities that can be exploited via the search parameter on the /academy/blogs endpoint and the string parameter at the /academy/course_bundles/search/query endpoint. These vulnerabilities differ from previous patches, specifically addressing gaps left unmitigated by the earlier fix for related XSS issues. Proper validation and sanitization of user inputs are crucial for mitigating potential security risks associated with these flaws.
