An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information.
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/