A high-severity SQL injection vulnerability was disclosed in Clickedu’s SaaS education management platform, tracked as CVE-2026-2247 (CVSS v4.0 8.3, CWE-89). The issue occurs in the student report-card/bulletin generation workflow: after a user downloads a student’s report card from the “Day-to-day” section in the mobile app, a PDF URL is generated where the session token does not expire and remains valid for days. A remote attacker who is previously authenticated can append unusual characters after the id_alu parameter in that PDF URL to trigger boolean-based blind and time-based blind SQLi, potentially enabling access to sensitive database information.
INCIBE-CERT reported that Clickedu has remediated the issue in an integration released on 2026-01-26. Other disclosures in the same reporting stream—multiple vulnerabilities in Graylog (including a critical issue and several XSS findings) and multiple/stored XSS vulnerabilities in Kubysoft (e.g., SVG upload sanitization leading to stored script execution)—are separate advisories affecting different products and CVEs, and are not part of the Clickedu SQLi event.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
INCIBE-CERT and CVE tracking disclosed CVE-2026-2247, a SQL injection flaw in Clickedu's SaaS platform affecting student report card generation. The issue allows an authenticated remote attacker to manipulate a PDF URL from the mobile app's "Day-to-day" section to perform blind SQL injection and potentially access confidential database information.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.