Record summary

CVE-2020-5775 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.

Description

Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Instructure Canvas Learning Management System (LMS)

CVE ListCanvas LMS 2020-07-29affected

Nuclei templates

1
ProjectDiscoveryMEDIUMCanvas LMS v2020-07-29 - Blind Server-Side Request ForgeryCVSS 5.8

Canvas version 2020-07-29 is susceptible to blind server-side request forgery. An attacker can cause Canvas to perform HTTP GET requests to arbitrary domains and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.

Remediation

Apply the latest security patches provided by Canvas LMS to mitigate the vulnerability.

WeaknessesCWE-918
Authorsalph4byt3
Template tagscvecve2020ssrfoastblindtenableinstructurevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CPE: cpe:2.3:a:instructure:canvas_learning_management_service:2020-07-29:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2