Impact
An authenticated learner can retrieve correct quiz answers from the course status endpoint before completing the assessment, giving them an unfair advantage and undermining the integrity of educational evaluations. The vulnerability falls under CWE-200, indicating an information disclosure weakness that permits unauthorized access to sensitive data. Although the data disclosed is not personal, its availability distorts assessment outcomes and can erode trust in the learning platform.
Affected Systems
The affected product is Three Learning Koollab LMS; version details are not specified in the advisory, so all released versions are potentially vulnerable until a vendor patch is issued.
Risk and Exploitability
The CVSS score of 4.3 suggests moderate severity, while an EPSS score of less than 1% indicates a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires a legitimate login, so the attack path is limited to authenticated users. Nonetheless, the impact on assessment integrity warrants timely remediation.
OpenCVE Enrichment