{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-63230",
        "assignerOrgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "state": "PUBLISHED",
        "assignerShortName": "CSA",
        "dateReserved": "2026-07-16T02:33:02.673Z",
        "datePublished": "2026-07-29T06:11:58.862Z",
        "dateUpdated": "2026-07-29T15:23:22.173Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
                "shortName": "CSA",
                "dateUpdated": "2026-07-29T06:11:58.862Z"
            },
            "title": "Pre-authentication error-based SQL injection vulnerability",
            "datePublic": "2026-07-29T06:07:00.000Z",
            "affected": [
                {
                    "vendor": "Three Learning",
                    "product": "Koollab LMS",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "5.3.2"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A pre-authentication error-based SQL injection\nvulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database\ncontents, including personally identifiable information, credentials, and valid\nJWT tokens that may enable account takeover, via the SCORM report endpoint.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "A pre-authentication error-based SQL injection\nvulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database\ncontents, including personally identifiable information, credentials, and valid\nJWT tokens that may enable account takeover, via the SCORM report endpoint."
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.1,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
                    }
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-89",
                                "lang": "en",
                                "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-29T15:11:34.025490Z",
                                "id": "CVE-2026-63230",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-29T15:23:22.173Z"
                }
            }
        ]
    }
}