Junglewise Threat Intelligence

CVE-2026-63228: Three Learning Koollab LMS unrestricted image upload in feedback endpoint

CVE-2026-63228 · Severity: low · CVSS 2.6 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a cloud-based learning management system, contains a vulnerability that allows users to upload malicious files disguised as images. An attacker with a valid account could use the feedback registration feature to upload harmful content to the server. While the immediate impact is limited, this could be used as a stepping stone for more complex attacks against the platform's infrastructure.

Technical details

An unrestricted file upload vulnerability exists in Koollab LMS version 5.3.2 within the feedback mail registration endpoint. The application fails to properly validate the contents of uploaded files, allowing an authenticated attacker to bypass extension-based filters by disguising malicious payloads as image files. While the CVSS score is low due to high attack complexity and required user interaction, successful exploitation allows an attacker to place arbitrary content on the server, which could facilitate secondary attacks. The vendor, Three Learning, has patched this vulnerability across all cloud-hosted SaaS instances.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor patched cloud instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats