An improper access control vulnerability in
Koollab LMS allowed an
unauthenticated attacker to read another user's name, internal identifier,
scores, lesson status, lesson position, and cached lesson state via the SCORM
API endpoint.
References
Configurations
No configuration.
History
29 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 |
29 Jul 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-29 07:16
Updated : 2026-07-30 16:54
NVD link : CVE-2026-63236
Mitre link : CVE-2026-63236
CVE.ORG link : CVE-2026-63236
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
