top of page
perceptive_background_267k.jpg

A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, including p…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 08:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage, Identity & Access, Data Breach & Exfiltration

A pre-authentication error-based SQL injection vulnerability was discovered in Koollab LMS. The flaw allows unauthenticated attackers to read sensitive database contents via the SCORM report endpoint. Exposed data includes personally identifiable information, user credentials, and valid JWT tokens. Successful exploitation of leaked JWT tokens could enable full account takeover. No authentication is required to exploit the vulnerability, significantly increasing its risk. The vulnerability has been assigned CVE-2026-63230 and is rated high severity. Advisories have been issued by both NVD/NIST and the Cyber Security Agency of Singapore (CSA).

Technical details

Mitigation steps:

Affected products:

Koollab LMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page