PT-2026-48222 · Ellucian · Banner Self-Service
CVE-2026-47106
·
Published
2026-06-09
·
Updated
2026-06-10
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ellucian Banner Self-Service versions prior to 2025-04-23
Description
The course search functionality contains a stored cross-site scripting issue. Authenticated Banner ERP users with write access can inject malicious JavaScript into faculty and course fields due to missing HTML encoding during DOM insertion. The malicious payloads are stored in fields such as
displayName, emailAddress, subjectDescription, or courseTitle. These values are then served unsanitized through the 'getFacultyMeetingTimes' API endpoint, leading to arbitrary script execution in the browser of any user viewing the affected course meeting times.Recommendations
Update to the April T2 release (2025-04-23) or a newer version.
Restrict write access to faculty and course fields to authorized personnel only to minimize the risk of payload injection.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Banner Self-Service