CVE-2021-36539

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).

The open LMS by Instructure, Inc.
GitHubGitHub
6.67K
Gain access to any uploaded files in your class via DocViewer using an exploitation in Canvas API v1.
GitHubGitHub
1