What is CVE-2026-63227?
This is an unrestricted file upload vulnerability in Koollab LMS, where an authenticated module designer can upload a SCORM package containing a PHP webshell to a publicly accessible directory. This allows for arbitrary code execution on the server. It is recommended to enforce strict file upload restrictions at the administrative level.
Azərbaycanca: Bu, Koollab LMS-də autentifikasiya olunmuş modul dizaynerinə SCORM paketi vasitəsilə PHP webshell yükləməyə imkan verən məhdudiyyətsiz fayl yükləmə zəifliyidir. Hücumçu serverdə ixtiyari kod icra edə bilər. Administrativ səviyyədə fayl yükləmə məhdudiyyətlərinin sərtləşdirilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434; shared vendor: Koollab
FAQ2
What level of access does an attacker need in Koollab LMS to exploit CVE-2026-63227?
The attacker must be an authenticated module designer.
What is the potential impact of successfully exploiting CVE-2026-63227?
It can lead to arbitrary code execution on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.