Executive brief
Ellucian Advance, a software suite used by higher education institutions for fundraising and donor management, contains a security flaw in its reporting tools. An authorized user could exploit this vulnerability to gain unauthorized access to sensitive database information, potentially compromising donor records and financial data. This issue affects both the Web and Legacy versions of the product, but does not impact Ellucian CRM Advance.
Technical details
A SQL injection vulnerability (CWE-89) exists within the Giving Reports functionality of Ellucian Advance Web and Legacy Advance. The flaw is located in the 'class credit' field, where improper neutralization of special elements allows for the execution of arbitrary SQL commands. An authenticated attacker with network access can exploit this to extract sensitive data from the underlying database. The vulnerability affects all versions prior to the AWA-2022-ORA-17 hotfix. Ellucian CRM Advance is confirmed to be unaffected.
Affected products
- Ellucian Advance Web All versions before AWA-2022-ORA-17
- Ellucian Legacy Advance All versions before AWA-2022-ORA-17
Timeline
- 2026-04-24: disclosed: SRA submits vulnerability to vendor
- 2026-05-15: patched: Vendor releases hotfix AWA-2022-ORA-17
- 2026-07-28: advisory: SRA publishes CVE and advisory