CVE-2026-6881
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
28/07/2026
Last modified:
29/07/2026
Description
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.<br />
<br />
<br />
<br />
This issue affects Advance Web: all versions; Legacy Advance: all versions.<br />
<br />
<br />
<br />
Ellucian CRM Advance is not impacted.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



