Business Logic Flaw in Koollab LMS: Impacting Lesson Completion Status
CVE-2026-63242
4.3MEDIUM
What is CVE-2026-63242?
A business logic flaw in Koollab LMS enables authenticated learners to manipulate lesson completion statuses through the SCORM commit endpoint. This vulnerability allows users to mark lessons as completed without engaging with the actual lesson content, thereby undermining the integrity of training and completion records. Organizations utilizing Koollab LMS should be aware of this issue to avoid potential misuse and ensure accurate tracking of learner progress.
Affected Version(s)
Koollab LMS 5.3.2
