Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fpv-9r28-747f

Опубликовано: 29 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.

EPSS

Процентиль: 2%
0.00122
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.4
nvd
14 дней назад

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.

EPSS

Процентиль: 2%
0.00122
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-798