Junglewise Threat Intelligence

CVE-2026-3007: Three Learning Koollab LMS stored XSS in courselet feature

CVE-2026-3007 · Severity: medium · CVSS 5.4 · Published 2026-04-23

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a learning management system used for e-learning, contains a security flaw in its courselet feature. An attacker can use this vulnerability to inject malicious scripts that run when other users view specific content. This could allow an attacker to hijack user sessions, steal sensitive information, or perform unauthorized actions on behalf of students or administrators.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Koollab LMS version 5.3.2 within the 'courselet' feature. The application fails to properly neutralize user-supplied input before storing it and displaying it to other users (CWE-79). An attacker with low-level privileges can inject malicious JavaScript into a courselet, which is then executed in the browser of any user who accesses that feature. This can lead to session hijacking or unauthorized data access. The vulnerability is addressed in version 5.4.0.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-23: disclosed: Initial disclosure by CSA Singapore
  • 2026-04-23: patched: Version 5.4.0 released to address the issue
  • 2026-04-23: advisory

References

Related threats