Boletines de Vulnerabilidades

CVE-2026-63231

   
Software afectado ORACLE
 
A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-face runs update endpoint to read the entire application database
and obtain valid JWT tokens for account takeover.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-63231