VYPR
Unrated severityNVD Advisory· Published Jul 28, 2026· Updated Jul 29, 2026

Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance

CVE-2026-6881

Description

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.

This issue affects Advance Web: all versions; Legacy Advance: all versions.

Ellucian CRM Advance is not impacted.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.