Executive brief
Koollab LMS is a cloud-based learning management system used for corporate training and assessments. A security flaw allowed authorized course designers to upload malicious files disguised as training packages. This could allow an attacker to take full control of the server, potentially leading to the theft of sensitive student data or a complete service shutdown.
Technical details
An unrestricted file upload vulnerability exists in the SCORM package upload functionality of Koollab LMS. An authenticated attacker with 'module designer' privileges can upload a SCORM package containing a PHP webshell. Because the application fails to validate the contents of the package and stores it in a publicly accessible directory, the attacker can execute arbitrary code on the server by requesting the uploaded PHP file. The vendor has patched this vulnerability across all cloud-hosted instances, and as a SaaS product, no user action is required.
Affected products
- Three Learning Koollab LMS 5.3.2
Timeline
- 2026-04-14: disclosed: Vendor disclosure
- 2026-04-26: patched: Vendor patched cloud instances
- 2026-07-29: advisory: Public release of advisory