CVE-2023-49339

MEDIUM

Ellucian Banner 9.17 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-49339. PoCs published by 3zizme.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-49339, an Insecure Direct Object Reference (IDOR) vulnerability in the Ellucian Banner System. It includes steps to reproduce the vulnerability, affected versions, and recommended mitigation strategies.

Description

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

Exploits (1)

nomisec WRITEUP 3 stars
by 3zizme · poc
https://github.com/3zizme/CVE-2023-49339

This repository provides a detailed technical analysis of CVE-2023-49339, an Insecure Direct Object Reference (IDOR) vulnerability in the Ellucian Banner System. It includes steps to reproduce the vulnerability, affected versions, and recommended mitigation strategies.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Ellucian Banner System version 9.17 and earlier
Auth required
Prerequisites: Legitimate user credentials · Access to the affected endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 6.5
EPSS 0.0059
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
ellucian/banner < 9.17
Published Feb 13, 2024
Tracked Since Feb 18, 2026