CVE-2023-49339: Ellucian Banner

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

Affected products

  • Ellucian Banner: up to and including 9.17

Published 2024-02-13. Last modified 2026-06-17.