PT-2026-65702 · Unknown · Koollab Lms
CVE-2026-63231
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Koollab LMS (affected versions not specified)
Description
A post-authentication SQL injection allows an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT (JSON Web Tokens) for account takeover. An error-based SQL oracle is a technique where the attacker uses database error messages to extract data from the system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Koollab Lms