Back

HIGH

SQL Injection in Clickedu's SaaS platform

Published Feb 17, 2026

Description

SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’ section from the mobile application.

In the URL of the generated PDF, the session token used does not expire, so it remains valid for days after its generation, and unusual characters can be entered after the ‘id_alu’ parameter, resulting in two types of SQLi: boolean-based blind and time-based blind. Exploiting this vulnerability could allow an attacker to access confidential information in the database.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by the Clickedu team in the integration of 26/01.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Feb 17, 2026
Updated Feb 17, 2026
Reserved Feb 9, 2026
CISA Vulnrichment
Updated Feb 17, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a