Impact
The vulnerability involves a CWE‑347 weakness, allowing an attacker to provide a client‑controlled seed to generate a one‑time password that matches the expected value, thereby bypassing the second factor of authentication. This flaw enables unauthorized access to administrator accounts in Koollab LMS.
Affected Systems
Three Learning: Koollab LMS is affected. No version information is available, so all existing installations should be considered potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 4.8 categorises the issue as medium severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote through the web interface where an attacker can supply the seed via the login or OTP entry form. Successful exploitation would grant the attacker administrator privileges.
OpenCVE Enrichment