What is CVE-2026-63230?
CVE-2026-63230 is a pre-authentication error-based SQL injection vulnerability in Koollab LMS, exploitable via the SCORM report endpoint. It allows unauthenticated attackers to extract sensitive database contents, including PII, credentials, and JWT tokens, potentially leading to account takeover. Apply the vendor's patch immediately to mitigate the risk.
Azərbaycanca: CVE-2026-63230, Koollab LMS platformasında autentifikasiya tələb etməyən error-based SQL injection zəifliyidir. Bu zəiflik SCORM hesabat endpointi vasitəsilə verilənlər bazasındakı şəxsi məlumatlar, giriş bilgiləri və JWT tokenlərinin oxunmasına imkan yaradır. Təhlükəsizlik üçün Koollab LMS təchizatçısının təqdim etdiyi yeniləməni dərhal tətbiq edin.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Koollab
FAQ2
What data can an attacker obtain by exploiting CVE-2026-63230?
An attacker can read personally identifiable information (PII), credentials, and JWT tokens from the database.
What measure should be taken to mitigate CVE-2026-63230?
The patch provided by the Koollab LMS vendor should be applied immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.