CVE-2026-63234
Three Learning · Koollab LMS
Koollab LMS contains a SQL injection and unsafe deserialisation vulnerability in the manual mark assessment endpoint, allowing authenticated attackers to execute arbitrary code.
Executive summary
An authenticated remote code execution vulnerability in Koollab LMS poses a critical risk to server integrity and data confidentiality.
Vulnerability
This vulnerability involves a combination of SQL injection and unsafe deserialization within the manual mark assessment endpoint. An authenticated attacker can manipulate serialized data to achieve arbitrary code execution and install a webshell on the host server.
Business impact
The ability for an authenticated attacker to execute arbitrary code on the server represents a total compromise of the application environment. Given the critical CVSS score of 9.9, this flaw could lead to full data exfiltration, unauthorized modification of assessment records, and potential lateral movement into the wider corporate network.
Remediation
Immediate Action: Upgrade Three Learning Koollab LMS to the latest available version provided by the vendor.
Proactive Monitoring: Review application access logs for unusual patterns involving the manual mark assessment endpoint and investigate any unauthorized file creation within the web directory.
Compensating Controls: Implement strict input validation and restrict access to the assessment module to authorized administrative personnel only until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full system compromise, administrators must prioritize patching this system immediately. Failure to update the software leaves the server exposed to complete takeover by any authenticated user.