CyberRota
← Ana sayfaya dön

CVE-2026-32856

MEDIUM · CVSS 6.1 EPSS %0.22

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-09T20:16:34.363 · Çekilme zamanı: 2026-06-30T12:15:28.533402+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-32856
Severity
MEDIUM
CVSS
6.1
EPSS
%0.22
Java

Orijinal NVD Açıklaması

Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in the dateConverter endpoint. Attackers can craft a malicious URL targeting the unauthenticated dateConverter endpoint to steal session cookies or perform other malicious actions in the context of the victim's browser session.