SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63228

LOW · CVSS 2.6 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

An unrestricted image upload vulnerability in Koollab LMS allows authenticated attackers to upload malicious content disguised as image files through the feedback mail registration endpoint. This could lead to further exploitation of the server, potentially compromising its integrity and security. Organizations using Koollab LMS should prioritize addressing this vulnerability to mitigate the risk of server-side attacks.

CVE
CVE-2026-63228
Severity
LOW
CVSS
2.6
EPSS
0.13%

Original NVD Description

An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.