Executive brief
Koollab LMS, a cloud-based learning management system used for corporate training and assessments, contains a security flaw in its face-to-face training update feature. An authorized user, such as a student or instructor, could exploit this flaw to access the entire underlying database. This could lead to the theft of sensitive personal information, login credentials, and security tokens, potentially allowing the attacker to take over other user accounts, including those of administrators.
Technical details
A post-authentication SQL injection vulnerability exists in Koollab LMS version 5.3.2 within the 'face-to-face runs update' endpoint. The flaw is rooted in insufficient sanitization of user-supplied input, allowing an authenticated attacker to perform error-based SQL injection. By leveraging an error-based SQL oracle, an attacker can exfiltrate sensitive data from the entire application database, including personally identifiable information (PII) and JSON Web Tokens (JWTs). These tokens can subsequently be used to facilitate account takeover. The vendor has patched all cloud-hosted (SaaS) instances, and no user action is required.
Affected products
- Three Learning Koollab LMS 5.3.2
Timeline
- 2026-04-14: disclosed: Vendor disclosure
- 2026-04-26: patched: Vendor patched cloud instances
- 2026-07-29: advisory: Public release of advisory