Unrestricted File Upload Vulnerability in Koollab LMS by Koollab
CVE-2026-63227

9.9CRITICAL

What is CVE-2026-63227?

An unrestricted file upload vulnerability in Koollab LMS can be exploited by authenticated module designers to upload SCORM packages containing malicious PHP webshells. This security flaw allows the execution of arbitrary code in a publicly accessible directory, jeopardizing the integrity and security of the server environment.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.