CVE-2026-63227
Received Received - Intake

Unrestricted SCORM File Upload in Koollab LMS Leads to RCE

Vulnerability report for CVE-2026-63227, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: CSA

Description

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
three_learning koollab_lms 5.3.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unrestricted SCORM file upload vulnerability in Koollab LMS version 5.3.2. An authenticated module designer can upload a SCORM package containing a PHP webshell to a publicly accessible directory. This allows the attacker to execute arbitrary code on the server.

Detection Guidance

Check for unauthorized PHP files in publicly accessible directories, particularly in SCORM package upload locations. Review web server access logs for suspicious uploads or execution attempts. Look for unexpected PHP webshell files in directories like /uploads or /scorm.

Impact Analysis

An attacker could gain full control of the server hosting Koollab LMS. This could lead to data theft, unauthorized access to sensitive information, disruption of services, or further compromise of connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and security. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Apply the official patch from Three Learning for cloud-hosted instances. If using an older version, update to the latest fixed release immediately. Disable SCORM uploads if not required or restrict upload permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63227. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart