What is CVE-2026-63231?
This is a post-authentication SQL injection vulnerability in Koollab LMS that allows an authenticated attacker to read the entire application database using an error-based SQL oracle via the face-to-face runs update endpoint. Exploitation can lead to obtaining valid JWT tokens for account takeover. Immediate patching as per vendor instructions is required.
Azərbaycanca: Bu, Koollab LMS sistemində autentifikasiya olunmuş istifadəçilər tərəfindən istifadə edilə bilən post-authentication SQL injection zəifliyidir. Zəiflik 'face-to-face runs update endpoint' vasitəsilə error-based SQL oracle texnikası ilə bütün verilənlər bazasını oxumağa və etibarlı JWT tokenlər əldə edərək hesab ələ keçirməyə imkan verir. Təsirə məruz qalmamaq üçün dərhal təchizatçı tərəfindən təqdim edilən təhlükəsizlik yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Koollab
FAQ2
What can an attacker obtain by exploiting the CVE-2026-63231 SQL injection vulnerability in Koollab LMS?
An authenticated attacker can read the entire application database using an error-based SQL oracle and obtain valid JWT tokens for account takeover.
What should be done to mitigate the CVE-2026-63231 vulnerability?
Immediate patching as per vendor instructions is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.