CVE-2023-49339: Ellucian Banner
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.
Affected products
- Ellucian Banner: up to and including 9.17
Published 2024-02-13. Last modified 2026-06-17.