CVE-2026-63232
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment r
CVSS
9.9
Crítico
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 29 jul 2026 · Última mod.: 30 jul 2026 · CWE-89
0.3%EPSS · 30 días0.3%
2026-08-102026-09-07
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-697168.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.1hCVE-2026-696366.5 MED—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.1hCVE-2026-673708.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.1hCVE-2026-668208.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.1hCVE-2026-668198.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.1hCVE-2026-628958.8 ALT—
———Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.1h