Koollab
Koollab LMS: vulnerabilidades y CVE
Koollab LMS tiene 17 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses17
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63242 | Media (4.3) | 0.25% | — | 29 jul 2026 | A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training… |
| CVE-2026-63241 | Baja (3.1) | 0.22% | — | 29 jul 2026 | An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress… |
| CVE-2026-63240 | Media (4.3) | 0.29% | — | 29 jul 2026 | An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment legitimately, compromising the… |
| CVE-2026-63239 | Media (5.4) | 0.21% | — | 29 jul 2026 | A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job… |
| CVE-2026-63238 | Media (6.5) | 0.34% | — | 29 jul 2026 | An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials… |
| CVE-2026-63237 | Media (4.8) | 0.18% | — | 29 jul 2026 | A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor,… |
| CVE-2026-63236 | Baja (3.7) | 0.26% | — | 29 jul 2026 | An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM… |
| CVE-2026-63235 | Baja (3.7) | 0.31% | — | 29 jul 2026 | An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial… |
| CVE-2026-63234 | Crítica (9.9) | 0.53% | — | 29 jul 2026 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to… |
| CVE-2026-63233 | Crítica (9.9) | 0.53% | — | 29 jul 2026 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell… |
| CVE-2026-63232 | Crítica (9.9) | 0.53% | — | 29 jul 2026 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell… |
| CVE-2026-63231 | Alta (8.1) | 0.45% | — | 29 jul 2026 | A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and… |
| CVE-2026-63230 | Crítica (9.1) | 0.52% | — | 29 jul 2026 | A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid… |
| CVE-2026-63229 | Crítica (9.1) | 0.52% | — | 29 jul 2026 | A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including… |
| CVE-2026-63228 | Baja (2.6) | 0.21% | — | 29 jul 2026 | An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling… |
| CVE-2026-63227 | Crítica (9.9) | 0.59% | — | 29 jul 2026 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code… |
| CVE-2026-3007 | Media (5.4) | 0.23% | — | 23 abr 2026 | Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature. |