Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Users and administrators of the affected product version are advised to update to the latest version 5.4.0 immediately.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Apr 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature. | |
| Title | Stored Cross-Site Scripting (XSS) Vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CSA
Published:
Updated: 2026-04-23T02:54:25.444Z
Reserved: 2026-02-23T05:15:43.206Z
Link: CVE-2026-3007
No data.
Status : Received
Published: 2026-04-23T04:16:07.980
Modified: 2026-04-23T04:16:07.980
Link: CVE-2026-3007
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.