A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.
This issue affects Advance Web: all versions; Legacy Advance: all versions.
Ellucian CRM Advance is not impacted.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://labs.sra.io/posts/ellucian |
|
History
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellucian
Ellucian advance Web Ellucian legacy Advance |
|
| Vendors & Products |
Ellucian
Ellucian advance Web Ellucian legacy Advance |
Wed, 29 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted. | |
| Title | Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: SRA
Published:
Updated: 2026-07-29T13:43:54.334Z
Reserved: 2026-04-22T18:56:43.654Z
Link: CVE-2026-6881
Updated: 2026-07-29T13:43:49.859Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T15:10:38Z