CVE-2026-63227

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
29/07/2026
Last modified:
30/07/2026

Description

An unrestricted SCORM file upload vulnerability<br /> in Koollab LMS allowed<br /> an authenticated module designer to upload a SCORM package containing a PHP<br /> webshell to a publicly accessible directory and execute arbitrary code on the<br /> server.

References to Advisories, Solutions, and Tools