What is CVE-2026-63228?
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious files disguised as images via the feedback mail registration endpoint. This could lead to further server-side attacks, and affected users are advised to apply patches immediately.
Azərbaycanca: Koollab LMS-də autentifikasiya olunmuş istifadəçinin 'feedback mail registration' bölməsi vasitəsilə zərərli faylları şəkil kimi yükləməsinə imkan verən 'unrestricted image upload' zəifliyi aşkarlanıb. Bu, serverdə əlavə hücumlara səbəb ola bilər, istifadəçilərə dərhal yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434; shared vendor: Koollab
FAQ2
What type of file upload vulnerability can an authenticated user exploit in Koollab LMS via the feedback mail registration section?
The vulnerability allows an authenticated user to upload malicious files disguised as images through an unrestricted image upload in the feedback mail registration endpoint.
If this unrestricted image upload vulnerability is successfully exploited, what type of threat could it lead to?
Successful exploitation could lead to further server-side attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.