Impact
An authenticated SQL injection flaw exists in the Giving Reports feature of Ellucian Advance Web and Legacy Advance. By inserting a crafted SQL query into the class credit field, an attacker can retrieve confidential information from the underlying database. This vulnerability is categorized as CWE-89 and can lead to unauthorized disclosure of sensitive data, compromising confidentiality and potentially allowing further exploitation.
Affected Systems
All released versions of Ellucian Advance Web and all releases of Legacy Advance are affected. Ellucian CRM Advance is not impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authentication, the attack vector is likely limited to users with legitimate access to the application, from which an attacker can manipulate the class credit field to run arbitrary SQL commands.
OpenCVE Enrichment