GHSA-4fpv-9r28-747fMediumCVSS 5.4

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access...

Published
July 29, 2026
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.

🔗 References (3)