CyberRota Analysis
AI-GeneratedAn authenticated attacker can exploit a SQL injection and unsafe deserialization vulnerability in Koollab LMS through the assessment reinforcement endpoint, enabling them to manipulate data passed to the unserialize() function. This could lead to the execution of arbitrary code on the server, potentially allowing the attacker to write a webshell to a publicly accessible location. Organizations using Koollab LMS should prioritize addressing this critical vulnerability to prevent unauthorized access and potential system compromise.
Original NVD Description
A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.