Beyond CRTO: Skillable 12 Jul 2026 12 min read CVE TL;DR While working on the RTO course tooling, I found Skillable’s SCORM lab launch path trusted a userId the browser supplies for allocation, while validating only the SCORM token. Changing that