CVE-2023-49339
Published Feb 13, 2024Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.
Vendor/product archive
1 CVEs tagged to ellucian / banner — 0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.