Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Business logic vulnerability
Vulnerability Description
A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion records.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Three Learning Koollab LMS 安全漏洞
Vulnerability Description
Three Learning Koollab LMS是Three Learning公司的一款学习管理系统。 Three Learning Koollab LMS 5.3.2版本存在安全漏洞,该漏洞源于业务逻辑问题,允许已验证身份的学习者通过SCORM commit端点将课程完成状态设置为已完成,从而破坏培训和完成记录。
CVSS Information
N/A
Vulnerability Type
N/A