{"api_version":"v1","generated_at":"2026-10-10T07:25:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-an-unrestricted-scorm-file-upload-vulnerability-in-koollab-lms-allowed-an-authenticated-module-designer-to-upl-385e68fa817d","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Koollab LMS","next_cursor":null,"observations":[{"affected":"5.3.2","affected_versions_present":true,"cve_id":"CVE-2026-63227","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63227","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-29T15:23:37.653Z","patch_url":"","primary_source":"","published":"2026-07-29T06:05:49.837Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server."}}
