vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents, including
personally identifiable information, credentials, and valid JWT tokens that may
enable account takeover.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Three Learning
Three Learning koollab Lms |
|
| Vendors & Products |
Three Learning
Three Learning koollab Lms |
Wed, 29 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover. | |
| Title | Pre-authentication blind SQL injection vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CSA
Published:
Updated: 2026-07-29T19:25:12.904Z
Reserved: 2026-07-16T02:33:02.673Z
Link: CVE-2026-63229
Updated: 2026-07-29T19:16:51.930Z
Status : Deferred
Published: 2026-07-29T07:16:42.267
Modified: 2026-07-30T16:54:05.457
Link: CVE-2026-63229
No data.
OpenCVE Enrichment
Updated: 2026-08-03T14:00:07Z