Executive brief
Koollab LMS is a cloud-based learning management system used for corporate training and assessments. A flaw in the system's logic allows students to mark their lessons as completed without actually viewing the required training materials. This undermines the integrity of training records and compliance tracking, as users can bypass mandatory educational requirements.
Technical details
A business logic vulnerability exists within the SCORM commit endpoint of Koollab LMS version 5.3.2. An authenticated learner can send a direct request to this endpoint to update their lesson status to 'completed' without interacting with or viewing the actual lesson content. This is a failure in server-side validation of the learning workflow. The vendor, Three Learning, has patched this vulnerability across its cloud-hosted SaaS environment, so no user action is required.
Affected products
- Three Learning Koollab LMS 5.3.2
Timeline
- 2026-04-14: disclosed: Vendor disclosure
- 2026-04-26: patched: Vendor patched cloud instances
- 2026-07-29: advisory: Public release of advisory