CVE 5.1 MEDIUM

Ellucian Banner Self-Service Stored XSS via getFacultyMeetingTimes API_CVE-2026-47106

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search functionality that allows authenticated Banner ERP users to inject malicious payloads into faculty and course fields by exploiting missing HTML encoding during DOM insertion. Attackers can store malicious JavaScript in fields such as faculty displayName, emailAddress, subjectDescription, or courseTitle through the unauthenticated getFacultyMeetingTimes API endpoint, causing arbitrary script execution.

Basic Information

ID CVE-2026-47106
Source VulnCheck
Published Jun 9, 2026 at 19:15
Modified Jun 9, 2026 at 19:23

Affected Product

Vendor Ellucian
Product Banner Self-Service
Affected Versions Ellucian Banner Self-Service 0
Ellucian Banner Self-Service 9.41

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.