CVE-2026-63242
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/07/2026
Last modified:
30/07/2026
Description
A business logic vulnerability in Koollab LMS<br />
allowed an<br />
authenticated learner to set their lesson completion status to completed via<br />
the SCORM commit endpoint without viewing the lesson material, compromising<br />
training and completion records.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM



