CVE-2026-63234

Three Learning · Koollab LMS

Koollab LMS contains a SQL injection and unsafe deserialisation vulnerability in the manual mark assessment endpoint, allowing authenticated attackers to execute arbitrary code.

Executive summary

An authenticated remote code execution vulnerability in Koollab LMS poses a critical risk to server integrity and data confidentiality.

Vulnerability

This vulnerability involves a combination of SQL injection and unsafe deserialization within the manual mark assessment endpoint. An authenticated attacker can manipulate serialized data to achieve arbitrary code execution and install a webshell on the host server.

Business impact

The ability for an authenticated attacker to execute arbitrary code on the server represents a total compromise of the application environment. Given the critical CVSS score of 9.9, this flaw could lead to full data exfiltration, unauthorized modification of assessment records, and potential lateral movement into the wider corporate network.

Remediation

Immediate Action: Upgrade Three Learning Koollab LMS to the latest available version provided by the vendor.

Proactive Monitoring: Review application access logs for unusual patterns involving the manual mark assessment endpoint and investigate any unauthorized file creation within the web directory.

Compensating Controls: Implement strict input validation and restrict access to the assessment module to authorized administrative personnel only until the patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for full system compromise, administrators must prioritize patching this system immediately. Failure to update the software leaves the server exposed to complete takeover by any authenticated user.