S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-5775 Scanner

CVE-2020-5775 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Canvas LMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-5775
5.8
CVSS

Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Instructure Canvas Learning Management System (LMS)by n/a
Canvas LMS 2020-07-29
Updated Aug 21, 2026View on NVD →
Detail

Canvas LMS is a learning management system that is widely used across educational institutions and organizations. It provides a platform for managing learning activities, including course creation, assessment, and communication with students. Canvas LMS is a cloud-based solution that is accessible from anywhere, making it a popular choice for organizations looking for a flexible and scalable system to manage their learning programs.

Recently, a security vulnerability was detected in Canvas LMS, CVE-2020-5775. This vulnerability allows a remote attacker to exploit a server-side request forgery flaw in the application, enabling them to conduct HTTP GET requests to any domain. With this ability, an attacker can potentially steal sensitive data, including login credentials and personal information of the end-users. 

If this vulnerability is exploited, it can lead to a severe security breach that can cause significant damage to organizations using Canvas LMS. This breach can result in data theft, unauthorized access to sensitive information, and reputation damage. Moreover, exploiting this vulnerability can lead to additional attacks that can further compromise the security of the system.

With the help of the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. s4e.io provides reliable, accurate, and timely information on security vulnerabilities that can affect their digital assets. With our platform, users can get up-to-date information on the latest security threats, so they can take the necessary precautions to protect their digital assets. Our community-based platform helps users connect with other security professionals and learn from their experiences to improve their security posture. With s4e.io, users can rest assured that they are getting the best possible protection for their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of Canvas LMS should take the following precautions:

  • Update to the latest version of Canvas LMS. 
  • Block access to unnecessary ports to mitigate the risk of server-side request forgery. 
  • Implement strict access control policies and monitor network traffic regularly. 
  • Train users on how to identify and report suspicious emails and phishing attempts. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-5775 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Canvas LMS S4E