An improper access control vulnerability in Koollab LMS...
Low severity
Unreviewed
Published
Jul 29, 2026
to the GitHub Advisory Database
•
Updated Jul 29, 2026
Description
Published by the National Vulnerability Database
Jul 29, 2026
Published to the GitHub Advisory Database
Jul 29, 2026
Last updated
Jul 29, 2026
An improper access control vulnerability in
Koollab LMS allowed an
unauthenticated attacker to read another user's name, internal identifier,
scores, lesson status, lesson position, and cached lesson state via the SCORM
API endpoint.
References