Vendors · instructure
Products (1)
Recent Vulnerabilities
View all 2 →CVE-2021-36539MEDIUM 6.5
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).
CVE-2020-5775MEDIUM 5.8
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
