NA

CVE-2023-49339

Published: 13/02/2024 Updated: 13/02/2024

Vulnerability Summary

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

Github Repositories

Critical Security Vulnerability in Ellucian Banner System

CVE-2023-49339 Security Vulnerability Report: Ellucian Banner System Introduction This document outlines a critical security vulnerability found in the Ellucian Banner System, particularly in version 917 and earlier versions The vulnerability has been identified in systems used by various universities in Saudi Arabia, potentially exposing sensitive student data Vulnerability