← Zurück zur CVE-Suche

CVE-2026-63230

Koollab LMS

Beschreibung

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint.

CVSS 9.1EPSS 0.296%Risiko 0.93
Quelle öffnen
Veröffentlicht
2026-07-29 07:16:42
Betroffene Versionen
unknown
Typ
Webanwendung
Zuletzt geändert
2026-07-30 16:54:05
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N