top of page
perceptive_background_267k.jpg

A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall answer endpoi…

Published:

29 juli 2026 om 00:00:00

Alert date:

29 juli 2026 om 10:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage, Zero-Day Vulnerabilities

A critical vulnerability (CVE-2026-63233) was identified in Koollab LMS involving SQL injection and unsafe deserialization. An authenticated attacker can exploit the assessment overall answer endpoint to inject malicious SQL and control data passed to PHP's unserialize() function. This allows the attacker to write a webshell to a publicly accessible server location. Once the webshell is in place, arbitrary code execution on the server becomes possible. The vulnerability chain combines two serious weaknesses: SQL injection and insecure deserialization. The issue was reported via NVD (NIST) and also flagged by the Cyber Security Agency of Singapore (CSA). The attack requires authentication, but the resulting impact is severe, enabling full server compromise. Organizations using Koollab LMS should apply patches or mitigations immediately.

Technical details

Mitigation steps:

Affected products:

Koollab LMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page