top of page
perceptive_background_267k.jpg

A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall answer endpoi…

Published:

29 July 2026 at 00:00:00

Alert date:

29 July 2026 at 10:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage, Zero-Day Vulnerabilities

A critical vulnerability (CVE-2026-63233) was identified in Koollab LMS involving SQL injection and unsafe deserialization. An authenticated attacker can exploit the assessment overall answer endpoint to inject malicious SQL and control data passed to PHP's unserialize() function. This allows the attacker to write a webshell to a publicly accessible server location. Once the webshell is in place, arbitrary code execution on the server becomes possible. The vulnerability chain combines two serious weaknesses: SQL injection and insecure deserialization. The issue was reported via NVD (NIST) and also flagged by the Cyber Security Agency of Singapore (CSA). The attack requires authentication, but the resulting impact is severe, enabling full server compromise. Organizations using Koollab LMS should apply patches or mitigations immediately.

Technical details

Mitigation steps:

Affected products:

Koollab LMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page