Information Disclosure in Koollab LMS Affects Learner Integrity
CVE-2026-63240
4.3MEDIUM
What is CVE-2026-63240?
An information disclosure vulnerability in Koollab LMS enables authenticated learners to access correct quiz answers via the course status endpoint, which undermines the integrity of assessments and gives students an unfair advantage by circumventing legitimate assessment processes.
Affected Version(s)
Koollab LMS 5.3.2
