Unrestricted image upload vulnerability
Summary
| CVE | CVE-2026-63228 |
|---|---|
| State | PUBLISHED |
| Assigner | CSA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-29 07:16:42 UTC |
| Updated | 2026-07-30 16:54:05 UTC |
| Description | An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server. |
Risk And Classification
Primary CVSS: v3.1 2.6 LOW from 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
EPSS: 0.001280000 probability, percentile 0.028820000 (date 2026-08-01)
Problem Types: CWE-434 | CWE-434 CWE-434 Unrestricted Upload of File with Dangerous Type
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4 | Secondary | 2.6 | LOW | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 2.6 | LOW | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Three Learning | Koollab LMS | affected 5.3.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094 | 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4 | www.csa.gov.sg | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.