Clickedu SaaS SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the Clickedu SaaS platform, specifically within the report generation feature. This vulnerability allows a previously authenticated remote attacker to execute malicious payloads by manipulating the 'id_alu' parameter in the URL of the generated PDF report. The session token used in the URL remains valid for several days, enabling the exploitation of this vulnerability to access confidential database information. The issue involves both boolean-based blind and time-based blind SQL injection techniques.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information stored in the database.

Remediation

The Clickedu team has fixed this vulnerability in the integration released on January 26, 2026.

Added: Feb 17, 2026, 12:18 PM
Updated: Feb 17, 2026, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.