SQL Injection Vulnerability in Koollab LMS by Koollab
CVE-2026-63231
8.1HIGH
What is CVE-2026-63231?
An identified SQL injection vulnerability in Koollab LMS enables an authenticated attacker to leverage an error-based SQL oracle through the face-to-face runs update endpoint. This exploitation allows complete access to the application's database, potentially resulting in an account takeover via valid JWT tokens.
Affected Version(s)
Koollab LMS 5.3.2
