What is CVE-2026-63234?
A critical vulnerability in Koollab LMS allows an authenticated attacker to exploit SQL injection and unsafe deserialisation via the ‘manual mark assessment’ endpoint. This could lead to remote code execution on the server, including writing a webshell to a publicly accessible location.
Azərbaycanca: Koollab LMS-də autentifikasiya olunmuş hücumçuya ‘manual mark assessment’ endpoint-i vasitəsilə SQL injection və unsafe deserialisation həyata keçirməyə imkan verən kritik zəiflikdir. Bu, serverdə ixtiyari kod icrasına və veb-qabıq yerləşdirməyə səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which endpoint does an authenticated attacker exploit for SQL injection in Koollab LMS?
An authenticated attacker exploits the ‘manual mark assessment’ endpoint for SQL injection.
What can successful exploitation of CVE-2026-63234 lead to on the server?
It could lead to remote code execution on the server, including writing a webshell to a publicly accessible location.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.