← Retour à la recherche de CVE

CVE-2026-63230

Koollab LMS

Description

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint.

CVSS 9.1EPSS 0.296%Risque 0.93
Voir la source
Publication
2026-07-29 07:16:42
Versions concernées
unknown
Type
Application web
Dernière modification
2026-07-30 16:54:05
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N