Vulnerabilities > CVE-2023-49339 - Authorization Bypass Through User-Controlled Key vulnerability in Ellucian Banner

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ellucian
CWE-639

Summary

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

Vulnerable Configurations

Part Description Count
Application
Ellucian
1