SQL Injection and Unsafe Deserialization Vulnerability in Koollab LMS
CVE-2026-63234

9.9CRITICAL

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63234?

A vulnerability in Koollab LMS allows authenticated attackers to exploit the manual mark assessment endpoint via SQL injection and unsafe deserialization. This flaw can enable attackers to manipulate data passed to the unserialize() function, potentially allowing them to write a web shell to a publicly accessible location, leading to the execution of arbitrary code on the server. Organizations using Koollab LMS should review their systems and apply necessary updates to mitigate potential risks.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.