CVE-2026-63233
🟠 Łataj w tym tygodniu
Wstrzyknięcie SQL i niebezpieczna deserializacja w Koollab LMS umożliwiają zdalne wykonanie kodu.
CVSS
9.9
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.
sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.9 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-07-29 07:16:42 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-30 16:54:05 UTC |
Referencje
- https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/ (5f57b9bf-260d-4433-bf07-b6a79e9bb7d4)