Impact
A vulnerable endpoint in Koollab LMS allows an authenticated user to inject SQL and pass crafted data to an unserialize function. The combination enables the attacker to write a webshell to a publicly accessible location and execute arbitrary code on the server, compromising confidentiality, integrity and availability.
Affected Systems
Vendor Three Learning offers the Koollab LMS product. No specific versions are listed in the advisory; the vulnerability applies to any affected release of this LMS.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, while the EPSS score of less than 1% shows a low current exploitation probability. The flaw is not yet in the CISA KEV catalog. Attack requires authentication and the use of the manual mark assessment endpoint; the attacker can control the data passed to unserialize, enabling code execution.
OpenCVE Enrichment