Three Learning Koollab LMS是Three Learning公司的一款学习管理系统。 Three Learning Koollab LMS 5.3.2版本存在安全漏洞,该漏洞源于业务逻辑问题,允许已验证身份的学习者通过SCORM commit端点将课程完成状态设置为已完成,从而破坏培训和完成记录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Three Learning | Koollab LMS | 5.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Three Learning | Koollab LMS | 5.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63233 | 9.9 CRITICAL | SQL injection and unsafe deserialisation vulnerability |
| CVE-2026-63234 | 9.9 CRITICAL | SQL injection and unsafe deserialisation vulnerability |
| CVE-2026-63232 | 9.9 CRITICAL | SQL injection and unsafe deserialisation vulnerability |
| CVE-2026-63230 | 9.1 CRITICAL | Pre-authentication error-based SQL injection vulnerability |
| CVE-2026-63229 | 9.1 CRITICAL | Pre-authentication blind SQL injection vulnerability |
| CVE-2026-63231 | 8.1 HIGH | Post-authentication SQL injection vulnerability |
| CVE-2026-63238 | 6.5 MEDIUM | Authentication bypass vulnerability |
| CVE-2026-63239 | 5.4 MEDIUM | Hard-coded AWS IAM credentials vulnerability |
| CVE-2026-63237 | 4.8 MEDIUM | TOTP two-factor authentication bypass vulnerability |
| CVE-2026-63240 | 4.3 MEDIUM | Information disclosure vulnerability |
| CVE-2026-63236 | 3.7 LOW | Improper access control vulnerability |
| CVE-2026-63235 | 3.7 LOW | Improper access control vulnerability |
| CVE-2026-63241 | 3.1 LOW | Insecure direct object reference vulnerability |
| CVE-2026-63228 | 2.6 LOW | Unrestricted image upload vulnerability |
No comments yet