Unrestricted Image Upload Vulnerability in Koollab LMS
CVE-2026-63228

2.6LOW

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63228?

The identified vulnerability in Koollab LMS permits authenticated attackers to upload harmful content, camouflaged as image files, through the feedback mail registration endpoint. This flaw might facilitate severe consequences for the server, enabling unauthorized access or other malicious activities. It is essential for users to ensure they are running the most recent version of Koollab LMS to mitigate such risks.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.