Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NDefault status
unaffected
5.3.2.
affected
Description
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.
Product status
5.3.2.
Credits
Justin Ng
References
www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-042/