Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hard-coded AWS IAM credentials vulnerability
Vulnerability Description
A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Three Learning Koollab LMS 安全漏洞
Vulnerability Description
Three Learning Koollab LMS是Three Learning公司的一款学习管理系统。 Three Learning Koollab LMS 5.3.2版本存在安全漏洞,该漏洞源于硬编码的AWS IAM凭证问题,可能导致攻击者访问共享多租户S3桶和SQS队列,暴露敏感数据,并实现恶意内容注入、作业操纵或电子邮件拦截。
CVSS Information
N/A
Vulnerability Type
N/A