top of page
perceptive_background_267k.jpg

A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark
assessment endpoint,…

Published:

29 juli 2026 om 00:00:00

Alert date:

29 juli 2026 om 10:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage

A critical vulnerability (CVE-2026-63234) was identified in Koollab LMS involving SQL injection combined with unsafe deserialization. An authenticated attacker can exploit the manual mark assessment endpoint to inject malicious SQL. The attacker can control data passed to PHP's unserialize() function, enabling object injection attacks. This chain of vulnerabilities allows writing a webshell to a publicly accessible server location. Once the webshell is deployed, the attacker can execute arbitrary code on the server. The vulnerability requires authentication but the impact is severe, enabling full server compromise. Both NVD and Singapore's CSA have published advisories regarding this issue.

Technical details

Mitigation steps:

Affected products:

Koollab LMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page