CVE-2020-5775
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 6.5%
from disclosure to weapon
Published on NVDAug 21
VulnCheck+1249d
exploitation probability
6.5%top 7% of all CVEs
observed exploitation
yesVulnCheck
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
Affected products
n/a · Instructure Canvas Learning Management System (LMS)