Reflected Cross-Site Scripting in Ellucian Banner Self-Service
CVE-2026-32856
5.1MEDIUM
What is CVE-2026-32856?
Ellucian Banner Self-Service prior to the April T2 release harbors a reflected cross-site scripting vulnerability. This allows unauthenticated attackers to execute arbitrary JavaScript within a user's browser by manipulating the toDateFormat request parameter in the dateConverter endpoint. By crafting a malicious URL aimed at this exposed endpoint, attackers can compromise user sessions, leading to the potential theft of session cookies and other malicious activities executed in the victim's browser context.
Affected Version(s)
Banner Self-Service 0
Banner Self-Service 0
Banner Self-Service 9.23
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdullah M. Alotaibi
Faris Almutairi
VulnCheck
