An insecure direct object reference
vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress
of any other user without authorisation, disclosing private learning progress
information.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-29 07:16
Updated : 2026-07-30 16:54
NVD link : CVE-2026-63241
Mitre link : CVE-2026-63241
CVE.ORG link : CVE-2026-63241
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
