CyberRota
← Ana sayfaya dön

CVE-2026-63232

CRITICAL · CVSS 9.9

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-29T07:16:42.600 · Çekilme zamanı: 2026-07-29T12:07:35.776385+00:00

CyberRota Yorumu

SQL Injection riski içeriyor.

CVE
CVE-2026-63232
Severity
CRITICAL
CVSS
9.9
EPSS
Yok

Orijinal NVD Açıklaması

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.