Impact
The vulnerability is a pre‑authentication blind SQL injection through the SSO OAuth endpoint. An unauthenticated attacker can employ a time‑based SQL oracle to extract sensitive data such as personally identifiable information, credentials, and JWT tokens, potentially enabling account takeover. This flaw is a classic SQL injection (CWE‑89) that compromises confidentiality and can lead to full credential compromise.
Affected Systems
The affected system is Three Learning’s Koollab Learning Management System. No specific version range is disclosed in the advisory, so all releases in use before a patch may be vulnerable.
Risk and Exploitability
The CVSS base score of 9.1 signals a high‑severity flaw. The EPSS score of less than 1% indicates that, at present, the exploitation probability is very low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is network‑based, as the vulnerability is exposed through the publicly reachable SSO OAuth endpoint, and no prior authentication is required, so any outsider can attempt the time‑based attack on any deployed instance.
OpenCVE Enrichment