


Perceptive Security
SOC/SIEM Consultancy

An unrestricted SCORM file upload vulnerability
in Koollab LMS allowed
an authenticated module designer to upload a SCORM package containing a PHP
webshell to a…
Published:
29 juli 2026 om 00:00:00
Alert date:
29 juli 2026 om 10:02:49
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities
CVE-2026-63227 is an unrestricted file upload vulnerability affecting Koollab LMS. An authenticated module designer can upload a malicious SCORM package containing a PHP webshell to a publicly accessible directory on the server. Once uploaded, the attacker can execute arbitrary code remotely, effectively achieving full server compromise. The vulnerability requires authentication as a module designer, but no further privilege escalation is needed to exploit it. This issue has been reported via NVD and flagged in a CSA Singapore security advisory. The risk is rated High due to the potential for remote code execution on affected servers.
Technical details
Mitigation steps:
Affected products:
Koollab LMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-63227
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
