Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SQL injection and unsafe deserialisation vulnerability
Vulnerability Description
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Three Learning Koollab LMS 安全漏洞
Vulnerability Description
Three Learning Koollab LMS是Three Learning公司的一款学习管理系统。 Three Learning Koollab LMS 5.3.2版本存在安全漏洞,该漏洞源于SQL注入和不安全反序列化,攻击者可通过评估总体答案端点注入,控制传递给unserialize()的数据,写入webshell到可公开访问位置,并在服务器上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A