


Perceptive Security
SOC/SIEM Consultancy

A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark
assessment endpoint,…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 08:02:49
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Database & Storage
A critical vulnerability (CVE-2026-63234) was identified in Koollab LMS involving SQL injection combined with unsafe deserialization. An authenticated attacker can exploit the manual mark assessment endpoint to inject malicious SQL. The attacker can control data passed to PHP's unserialize() function, enabling object injection attacks. This chain of vulnerabilities allows writing a webshell to a publicly accessible server location. Once the webshell is deployed, the attacker can execute arbitrary code on the server. The vulnerability requires authentication but the impact is severe, enabling full server compromise. Both NVD and Singapore's CSA have published advisories regarding this issue.
Technical details
Mitigation steps:
Affected products:
Koollab LMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-63234
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
