VYPR

LMS

by Koollab

CVEs (12)

  • CVE-2026-63242Jul 29, 2026
    risk 0.00cvss epss 0.00

    A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion records.

  • CVE-2026-63241Jul 29, 2026
    risk 0.00cvss epss 0.00

    An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information.

  • CVE-2026-63240Jul 29, 2026
    risk 0.00cvss epss 0.00

    An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment legitimately, compromising the integrity of assessments.

  • CVE-2026-63239Jul 29, 2026
    risk 0.00cvss epss 0.00

    A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.

  • CVE-2026-63236Jul 29, 2026
    risk 0.00cvss epss 0.00

    An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.

  • CVE-2026-63235Jul 29, 2026
    risk 0.00cvss epss 0.00

    An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.

  • CVE-2026-63234Jul 29, 2026
    risk 0.00cvss epss 0.00

    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code…

  • CVE-2026-63233Jul 29, 2026
    risk 0.00cvss epss 0.00

    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary…

  • CVE-2026-63231Jul 29, 2026
    risk 0.00cvss epss 0.00

    A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover.

  • CVE-2026-63230Jul 29, 2026
    risk 0.00cvss epss 0.00

    A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM…

  • CVE-2026-63229Jul 29, 2026
    risk 0.00cvss epss 0.00

    A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT…

  • CVE-2026-63227Jul 29, 2026
    risk 0.00cvss epss 0.00

    An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.