A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark
assessment endpoint, control data passed to unserialize(), write a webshell to
a publicly accessible location, and execute arbitrary code on the server.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Three Learning
Three Learning koollab Lms |
|
| Vendors & Products |
Three Learning
Three Learning koollab Lms |
Wed, 29 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. | |
| Title | SQL injection and unsafe deserialisation vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CSA
Published:
Updated: 2026-07-29T15:22:51.961Z
Reserved: 2026-07-16T02:33:02.674Z
Link: CVE-2026-63234
Updated: 2026-07-29T15:13:33.915Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T15:10:08Z