CVE-2026-6881

Severity CVSS v4.0:
CRITICAL
Type:
CWE-89 SQL Injection
Publication date:
28/07/2026
Last modified:
29/07/2026

Description

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.<br /> <br /> <br /> <br /> This issue affects Advance Web: all versions; Legacy Advance: all versions.<br /> <br /> <br /> <br /> Ellucian CRM Advance is not impacted.

References to Advisories, Solutions, and Tools