CVE-2026-63236
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4 (Secondary)
Description
An improper access control vulnerability in
Koollab LMS allowed an
unauthenticated attacker to read another user's name, internal identifier,
scores, lesson status, lesson position, and cached lesson state via the SCORM
API endpoint.
References (1)
Source: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
Timeline
No history available yet.