CVE-2020-5775
instructure canvas_learning_management_service Server-Side Request Forgery (SSRF)
Record summary
CVE-2020-5775 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.
Description
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
canvas_learning_management_serviceBrowse instructure / canvas_learning_management_service | VulnCheck | Version data not supplied | |
Instructure Canvas Learning Management System (LMS) | CVE List | Canvas LMS 2020-07-29 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMCanvas LMS v2020-07-29 - Blind Server-Side Request ForgeryCVSS 5.8
Canvas version 2020-07-29 is susceptible to blind server-side request forgery. An attacker can cause Canvas to perform HTTP GET requests to arbitrary domains and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.
Remediation
Apply the latest security patches provided by Canvas LMS to mitigate the vulnerability.
Source: ProjectDiscovery