LOWVulnerability
CVE-2026-6881
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field. This issue affects Advance Web: all versions; Legacy Advance: all versions. Ellucian CRM Advance is not impacted.
Properties
- epss_score
- 0.00203
- cve_id
- CVE-2026-6881
- published_at
- 2026-07-28T21:17:29.427
- last_modified
- 2026-09-09T15:52:04.827
- epss_percentile
- 0.10357
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph