Stored Cross-Site Scripting Vulnerability in Ellucian Banner Self-Service
CVE-2026-47106
5.1MEDIUM
What is CVE-2026-47106?
Ellucian Banner Self-Service prior to the April 2025 T2 release has a vulnerability that allows authenticated users to inject malicious scripts into critical faculty and course fields. Due to missing HTML encoding during DOM insertion, these manipulations can exploit the getFacultyMeetingTimes API endpoint, leading to unsanitized data exposure. As a result, any user accessing the affected course meeting times may unknowingly execute harmful JavaScript within their browser, jeopardizing data integrity and user security.
Affected Version(s)
Banner Self-Service 0
Banner Self-Service 0
Banner Self-Service 9.41
