CVE-2026-63242

Published Jul 29, 2026

Last updated 24 days ago

CVSS medium 4.3
Business logic

Overview

Description
A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion records.
Source
5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-639

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.