Back

CRITICAL

SQL injection and unsafe deserialisation vulnerability

Published Jul 29, 2026

Description

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CSA
Published Jul 29, 2026
Updated Jul 29, 2026
Reserved Jul 16, 2026
CISA Vulnrichment
Updated Jul 29, 2026
NVD
Status Deferred
Modified Jul 30, 2026
Red Hat
Severity n/a
Public date n/a