Description
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.



This issue affects Advance Web: all versions; Legacy Advance: all versions.



Ellucian CRM Advance is not impacted.
Published: 2026-07-28
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated SQL injection flaw exists in the Giving Reports feature of Ellucian Advance Web and Legacy Advance. By inserting a crafted SQL query into the class credit field, an attacker can retrieve confidential information from the underlying database. This vulnerability is categorized as CWE-89 and can lead to unauthorized disclosure of sensitive data, compromising confidentiality and potentially allowing further exploitation.

Affected Systems

All released versions of Ellucian Advance Web and all releases of Legacy Advance are affected. Ellucian CRM Advance is not impacted.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authentication, the attack vector is likely limited to users with legitimate access to the application, from which an attacker can manipulate the class credit field to run arbitrary SQL commands.

Generated by OpenCVE AI on August 3, 2026 at 14:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Ellucian’s vendor‑released patch or upgrade to a fixed version as soon as it becomes available.
  • Reduce the privileges of the database user account that the application uses so it has only the minimum permissions required.
  • Enforce strict input validation or use prepared statements for the class credit field in the Giving Reports interface.
  • Limit or disable the Giving Reports functionality for users who do not need it.

Generated by OpenCVE AI on August 3, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Ellucian
Ellucian advance Web
Ellucian legacy Advance
Vendors & Products Ellucian
Ellucian advance Web
Ellucian legacy Advance

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.
Title Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


Subscriptions

Ellucian Advance Web Legacy Advance
cve-icon MITRE

Status: PUBLISHED

Assigner: SRA

Published:

Updated: 2026-07-29T13:43:54.334Z

Reserved: 2026-04-22T18:56:43.654Z

Link: CVE-2026-6881

cve-icon Vulnrichment

Updated: 2026-07-29T13:43:49.859Z

cve-icon NVD

Status : Received

Published: 2026-07-28T21:17:29.427

Modified: 2026-07-29T14:16:35.623

Link: CVE-2026-6881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')