A business logic vulnerability in Koollab LMS
allowed an
authenticated learner to set their lesson completion status to completed via
the SCORM commit endpoint without viewing the lesson material, compromising
training and completion records.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-29 07:16
Updated : 2026-07-30 16:54
NVD link : CVE-2026-63242
Mitre link : CVE-2026-63242
CVE.ORG link : CVE-2026-63242
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
