PT-2026-65702 · Unknown · Koollab Lms

CVE-2026-63231

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Koollab LMS (affected versions not specified)
Description A post-authentication SQL injection allows an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT (JSON Web Tokens) for account takeover. An error-based SQL oracle is a technique where the attacker uses database error messages to extract data from the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63231

Affected Products

Koollab Lms