CyberRota Analysis
AI-GeneratedA post-authentication SQL injection vulnerability in Koollab LMS allows authenticated attackers to exploit the face-to-face runs update endpoint, enabling them to read the entire application database and retrieve valid JWT tokens for account takeover. This high-severity issue poses a significant risk to organizations using Koollab LMS, particularly those with sensitive user data. Organizations should prioritize patching this vulnerability to mitigate potential data breaches and unauthorized access.
Original NVD Description
A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover.