
Critical Security Vulnerability in Ellucian Banner System
This document outlines a critical security vulnerability found in the Ellucian Banner System, particularly in version 9.17 and earlier versions. The vulnerability has been identified in systems used by various universities in Saudi Arabia, potentially exposing sensitive student data.
/StudentSelfService/ssb/studentCard/retrieveDatabannerIdbannerId parameter in the URL to a different student's identifier.bannerIdThe vulnerability impacts the Ellucian Banner System, version 9.17 and earlier. It is crucial for institutions using these versions to take immediate action to mitigate the risks.
This vulnerability has been registered with the CVE ID: CVE-2023-49339. Further details and updates regarding the vulnerability will be provided as they become available.
Abdulaziz Naif Almadhi