CyberRota Analysis
AI-GeneratedAn insecure direct object reference vulnerability in Koollab LMS enables authenticated users to access and query the course completion progress of other users without proper authorization, leading to unauthorized disclosure of private learning progress data. Organizations using Koollab LMS should prioritize addressing this issue to protect user privacy and maintain compliance with data protection regulations. Although classified as low severity, the potential for privacy breaches warrants attention, especially in educational environments.
Original NVD Description
An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information.