Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfrq-3339-mcj4

Опубликовано: 28 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.4

Описание

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.

This issue affects Advance Web: all versions; Legacy Advance: all versions.

Ellucian CRM Advance is not impacted.

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.

This issue affects Advance Web: all versions; Legacy Advance: all versions.

Ellucian CRM Advance is not impacted.

EPSS

Процентиль: 10%
0.00203
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
8 дней назад

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.

EPSS

Процентиль: 10%
0.00203
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-89