SQL Injection and Unsafe Deserialization Vulnerability in Koollab LMS
CVE-2026-63232

9.9CRITICAL

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63232?

A vulnerability in Koollab LMS allows an authenticated attacker to exploit the assessment reinforcement endpoint via SQL injection and unsafe deserialization methods. This enables the attacker to manipulate data passed to the unserialize() function, potentially writing a web shell to an accessible location on the server. This compromise can lead to unauthorized execution of arbitrary code, posing significant threats to data integrity and system security.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.