Unrestricted SCORM File Upload Vulnerability in Koollab LMS: A Critical Threat
CVE-2026-63227 is a critical vulnerability in Koollab LMS that allows an authenticated module designer to upload a malicious SCORM package containing a PHP webshell, leading to arbitrary code execution on the server. This vulnerability has a CVSS score of 9.9 and is classified as CWE-434. Although not actively exploited, it poses a significant threat to affected systems.