A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
reinforcement endpoint, control data passed to unserialize(), write a webshell
to a publicly accessible location, and execute arbitrary code on the server.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. | |
| Title | SQL injection and unsafe deserialisation vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CSA
Published:
Updated: 2026-07-29T06:16:25.752Z
Reserved: 2026-07-16T02:33:02.674Z
Link: CVE-2026-63232
No data.
No data.
No data.
OpenCVE Enrichment
No data.