Impact
An insecure direct object reference vulnerability in Koollab LMS allows an authenticated user to query the course completion progress of any other user without authorization, disclosing private learning progress information. The flaw is a classic information‑disclosure issue identified as CWE‑639.
Affected Systems
The affected product is Koollab LMS from Three Learning. No specific version information is provided.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity. The EPSS score of less than 1% implies a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must first authenticate to a user account; from there they can request arbitrary progress data, leading to privacy violations.
OpenCVE Enrichment