SQL Injection and Unsafe Deserialization Vulnerability in Koollab LMS
CVE-2026-63232
9.9CRITICAL
What is CVE-2026-63232?
A vulnerability in Koollab LMS allows an authenticated attacker to exploit the assessment reinforcement endpoint via SQL injection and unsafe deserialization methods. This enables the attacker to manipulate data passed to the unserialize() function, potentially writing a web shell to an accessible location on the server. This compromise can lead to unauthorized execution of arbitrary code, posing significant threats to data integrity and system security.
Affected Version(s)
Koollab LMS 5.3.2
