Impact
The vulnerability is an authentication bypass that permits an unauthenticated attacker to take control of any account, including administrators, by submitting a valid user UUID to the 2FA validation endpoint without supplying primary credentials. This flaw arises from insufficient validation of authentication context and is classified as CWE‑287, an authentication bypass. An attacker can thereby gain full access to target accounts, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects Koollab Learning Management System by Three Learning. The CVE description does not specify affected versions, so all current releases are potentially vulnerable until a vendor patch is released.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity vulnerability. The EPSS score is below 1%, implying a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, which reduces urgency for immediate remediation. The attack vector appears to be unauthenticated access to the 2FA validation endpoint; an attacker only needs to know a valid user UUID, which could be obtained via enumeration or prior compromise. Given these constraints the overall risk is moderate yet significant, warranting prompt mitigation.
OpenCVE Enrichment