Clickedu SaaS SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in the Clickedu SaaS platform, specifically within the report generation feature. This vulnerability allows a previously authenticated remote attacker to execute malicious payloads by manipulating the 'id_alu' parameter in the URL of the generated PDF report. The session token used in the URL remains valid for several days, enabling the exploitation of this vulnerability to access confidential database information. The issue involves both boolean-based blind and time-based blind SQL injection techniques.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information stored in the database.
Remediation
The Clickedu team has fixed this vulnerability in the integration released on January 26, 2026.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
