Medium severity6.1NVD Advisory· Published Jun 9, 2026· Updated Jun 10, 2026
CVE-2026-32856
CVE-2026-32856
Description
Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in the dateConverter endpoint. Attackers can craft a malicious URL targeting the unauthenticated dateConverter endpoint to steal session cookies or perform other malicious actions in the context of the victim's browser session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2025-04-23
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.