Aaron(Yinghao) Li

1 exploit Active since Jan 2023
CVE-2021-36539 WRITEUP MEDIUM WORKING POC
Instructure Canvas LMS - Info Disclosure
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).
CVSS 6.5