CyberRota Analysis
AI-GeneratedAn improper access control vulnerability in Koollab LMS enables unauthenticated attackers to access sensitive user information, including names, internal identifiers, and lesson statuses, through the SCORM API endpoint. While the severity is rated low, organizations using Koollab LMS should prioritize remediation to protect user privacy and prevent potential data exposure. This is particularly relevant for educational institutions and organizations relying on this learning management system.
Original NVD Description
An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.