top of page
perceptive_background_267k.jpg

A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, including p…

Published:

29 juli 2026 om 00:00:00

Alert date:

29 juli 2026 om 10:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage, Identity & Access, Data Breach & Exfiltration

A pre-authentication error-based SQL injection vulnerability was discovered in Koollab LMS. The flaw allows unauthenticated attackers to read sensitive database contents via the SCORM report endpoint. Exposed data includes personally identifiable information, user credentials, and valid JWT tokens. Successful exploitation of leaked JWT tokens could enable full account takeover. No authentication is required to exploit the vulnerability, significantly increasing its risk. The vulnerability has been assigned CVE-2026-63230 and is rated high severity. Advisories have been issued by both NVD/NIST and the Cyber Security Agency of Singapore (CSA).

Technical details

Mitigation steps:

Affected products:

Koollab LMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page