Executive brief
Koollab LMS, a cloud-based learning management system used for corporate training and assessments, contained a critical security flaw in its reporting interface. An unauthorized attacker could exploit this vulnerability to access the underlying database without needing a password. This could result in the theft of sensitive information, including user credentials, personal data, and security tokens that allow attackers to take over user accounts.
Technical details
A pre-authentication error-based SQL injection vulnerability exists in the SCORM report endpoint of Koollab LMS. The flaw allows a remote, unauthenticated attacker to craft malicious SQL queries that trigger database error messages containing sensitive data. By analyzing these errors, an attacker can extract the entire contents of the database, including PII, user credentials, and active JWT tokens. The vendor, Three Learning, has patched this vulnerability across its SaaS environment; because the product is cloud-hosted, no manual customer action is required.
Affected products
- Three Learning Koollab LMS 5.3.2
Timeline
- 2026-04-14: disclosed: Vendor disclosure
- 2026-04-26: patched: Vendor patched cloud instances
- 2026-07-29: advisory: Public release of advisory