CyberRota Analysis
AI-GeneratedKoollab LMS is vulnerable to an authentication bypass that enables unauthenticated attackers to gain access to any user account, including those of administrators, by simply supplying a valid user UUID at the 2FA validation endpoint. This flaw poses a significant risk of account takeover and unauthorized access to sensitive information. Organizations using Koollab LMS should prioritize patching this vulnerability to safeguard their user accounts and prevent potential exploitation.
Original NVD Description
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.