CyberRota Analysis
AI-GeneratedThe SCORM lab launch endpoint in Skillable fails to properly validate the userId parameter against the authenticated session token, allowing authenticated users to manipulate this parameter. This vulnerability enables users to bypass lab launch rate limits, potentially leading to denial of service for other users by consuming their lab allocations. Organizations utilizing Skillable for training or exams should prioritize addressing this issue to protect user access and maintain equitable resource distribution.
Original NVD Description
The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. Skillable was formerly named Learn on Demand Systems.