CVE-2026-2247 describes a high-severity SQL injection vulnerability (CWE-89) in the Clicldeu SaaS platform, specifically affecting the report generation function within the mobile application's 'Day-to-day' section. An authenticated remote attacker can exploit this flaw by manipulating the URL when downloading a student's report card, leveraging a non-expiring session token and the 'id_alu' parameter to execute boolean-based blind or time-based blind SQLi. This could lead to unauthorized access to confidential database information. The vulnerability carries a CVSSv4 score of 8.3 (High) due to its network-based attack vector, low attack complexity, and high impact on confidentiality. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Clickedu | SaaS Platform | All versionsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.