CVE-2026-63230
CRITICALThree Learning Koollab Lms < 5.3.2 - SQL Injection
Title source: ruleDescription
A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint.
References (1)
Core 1
Core References
Scores
CVSS v3
9.1
EPSS
0.0030
EPSS Percentile
21.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
Three Learning/Koollab LMS
5.3.2
Published
Jul 29, 2026
Tracked Since
Jul 29, 2026