


Perceptive Security
SOC/SIEM Consultancy

A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall answer endpoi…
Published:
29 July 2026 at 00:00:00
Alert date:
29 July 2026 at 10:02:49
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Database & Storage, Zero-Day Vulnerabilities
A critical vulnerability (CVE-2026-63233) was identified in Koollab LMS involving SQL injection and unsafe deserialization. An authenticated attacker can exploit the assessment overall answer endpoint to inject malicious SQL and control data passed to PHP's unserialize() function. This allows the attacker to write a webshell to a publicly accessible server location. Once the webshell is in place, arbitrary code execution on the server becomes possible. The vulnerability chain combines two serious weaknesses: SQL injection and insecure deserialization. The issue was reported via NVD (NIST) and also flagged by the Cyber Security Agency of Singapore (CSA). The attack requires authentication, but the resulting impact is severe, enabling full server compromise. Organizations using Koollab LMS should apply patches or mitigations immediately.
Technical details
Mitigation steps:
Affected products:
Koollab LMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-63233
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
