Boletines de Vulnerabilidades

CVE-2026-63229

   
Software afectado ORACLE
 
A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents, including
personally identifiable information, credentials, and valid JWT tokens that may
enable account takeover.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-63229