CVE-2026-6881

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.
CVSS

No CVSS.

References
Configurations

No configuration.

History

28 Jul 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 21:17

Updated : 2026-07-29 14:16


NVD link : CVE-2026-6881

Mitre link : CVE-2026-6881

CVE.ORG link : CVE-2026-6881


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')