Loading market data...
← Back to CVE feed

CVE-2026-63228

LOW CVSS 2.6 View on NVD ↗

Description

An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Published: Jul 29, 2026 07:16 UTC Modified: Jul 29, 2026 16:17 UTC