Business Logic Flaw in Koollab LMS: Impacting Lesson Completion Status
CVE-2026-63242

4.3MEDIUM

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63242?

A business logic flaw in Koollab LMS enables authenticated learners to manipulate lesson completion statuses through the SCORM commit endpoint. This vulnerability allows users to mark lessons as completed without engaging with the actual lesson content, thereby undermining the integrity of training and completion records. Organizations utilizing Koollab LMS should be aware of this issue to avoid potential misuse and ensure accurate tracking of learner progress.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.