GHSA-xfrq-3339-mcj4Critical

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance...

Published
July 28, 2026
Last Modified
July 28, 2026

🔗 CVE IDs covered (1)

📋 Description

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.

This issue affects Advance Web: all versions; Legacy Advance: all versions.

Ellucian CRM Advance is not impacted.

🔗 References (3)