Executive brief
Koollab LMS, a cloud-based learning management system used for corporate training and assessments, contains a critical security flaw. An authorized user, such as a student or instructor, can exploit the assessment reinforcement feature to take full control of the server. This could lead to the theft of sensitive student data, complete service disruption, or the use of the platform to launch further attacks.
Technical details
A critical vulnerability exists in Koollab LMS version 5.3.2 due to a combination of SQL injection and unsafe deserialization. An authenticated attacker can exploit the assessment reinforcement endpoint to inject malicious data that is subsequently passed to the PHP unserialize() function. By controlling the serialized input, an attacker can achieve remote code execution (RCE), allowing them to write a webshell to a publicly accessible directory. This vulnerability is reachable over the network and requires low-level authentication. The vendor has patched all cloud-hosted instances, and as a SaaS product, no manual user action is required.
Affected products
- Three Learning Koollab LMS 5.3.2
Timeline
- 2026-04-14: disclosed: Vendor disclosure
- 2026-04-26: patched: Vendor patched cloud instances
- 2026-07-29: advisory: Public release of advisory