CVE-2026-2247
Last modified
CVE-2026-2247 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’ section from the mobile application. In the URL of the generated PDF, the session token used does not expire, so it remains valid for days after its generation, and unusual characters can be entered after the ‘id_alu’ parameter, resulting in two types of SQLi: boolean-based blind and time-based blind. Exploiting this vulnerability could allow an attacker to access confidential information in the database.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’ section from the mobile application. In the URL of the generated PDF, the session token used does not expire, so it remains valid for days after its generation, and unusual characters can be entered after the ‘id_alu’ parameter, resulting in two types of SQLi: boolean-based blind and time-based blind. Exploiting this vulnerability could allow an attacker to access confidential information in the database.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-2247?
How severe is CVE-2026-2247?
How do I fix CVE-2026-2247?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22464Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2026-22465Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-22466Missing Authorization vulnerability in Chandni Patel WP MapI…4.3
- CVE-2026-22467Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-22468Missing Authorization vulnerability in AbsolutePlugins Absol…4.3
- CVE-2026-22469Improper Neutralization of Script-Related HTML Tags in a Web…5.3
- CVE-2026-22470Improper Neutralization of Special Elements used in an SQL C…7.6
- CVE-2026-22471Deserialization of Untrusted Data vulnerability in maximsecu…8.8
- CVE-2026-22472Missing Authorization vulnerability in hassantafreshi Easy F…4.3
- CVE-2026-22473Deserialization of Untrusted Data vulnerability in designthe…8.8
- CVE-2026-22474Deserialization of Untrusted Data vulnerability in ThemeREX …9.8
- CVE-2026-22475Deserialization of Untrusted Data vulnerability in axiomthem…9.8
Are you affected by CVE-2026-2247?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
