Impact
The vulnerability is an improper access control flaw that lets an unauthenticated attacker retrieve sensitive data of other users—such as name, internal identifier, scores, lesson status, lesson position, and cached lesson state—through the SCORM API endpoint. This could potentially compromise user privacy (inferred). The weakness is identified as CWE‑284.
Affected Systems
The affected product is Koollab LMS from Three Learning. No specific version information is provided, so any deployed instance may be vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and the EPSS score of less than 1 % shows a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw from any open network connection that can reach the SCORM API endpoint (likely remote network). Authentication is not required, so the endpoint can be accessed by unauthenticated users.
OpenCVE Enrichment