Files
CVEs-PoC/2020/CVE-2020-5775.md
T
2024-05-25 21:48:12 +02:00

19 lines
790 B
Markdown

### [CVE-2020-5775](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5775)
![](https://img.shields.io/static/v1?label=Product&message=Instructure%20Canvas%20Learning%20Management%20System%20(LMS)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Server-Side%20Request%20Forgery&color=brighgreen)
### Description
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
### POC
#### Reference
- https://www.tenable.com/security/research/tra-2020-49
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates