CVE-2026-63228

LOW

Three Learning Koollab LMS - Unrestricted Image Upload Vulnerability

Title source: rule
STIX 2.1

Description

An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.

Scores

CVSS v3 2.6
EPSS 0.0013
EPSS Percentile 2.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
Three Learning/Koollab LMS 5.3.2
Published Jul 29, 2026
Tracked Since Jul 29, 2026