CVE-2026-63232

🟠 Łataj w tym tygodniu

Wstrzyknięcie SQL i niebezpieczna deserializacja w Koollab LMS umożliwiają zdalne wykonanie kodu.

CVSS
9.9
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.

sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-07-29 07:16:42 UTC
Ostatnia modyfikacja (NVD)2026-07-30 16:54:05 UTC
Referencje