Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): canvas lms
- Search Type: Search All
- CPE Name Search: false
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2021-36539 |
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url). Published: January 26, 2023; 4:15:23 PM -0500 |
V3.1: 6.5 MEDIUM V2.0:(not available) |
CVE-2020-5775 |
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains. Published: August 21, 2020; 2:15:11 PM -0400 |
V3.1: 5.8 MEDIUM V2.0: 5.0 MEDIUM |