Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yl4579

#41120de 53,638
6.5CVSS total
Vulnerabilidades · 1
PT-2023-12286
6.5
2023-01-26
Instructure · Instructure Canvas Lms · CVE-2021-36539
**Name of the Vulnerable Software and Affected Versions** Instructure Canvas LMS (affected versions not specified) **Description** The issue concerns improper access control in Instructure Canvas LMS, where unprivileged users can access locked or unpublished files through the DocViewer based file preview URL, referred to as `canvadoc session url`. This allows unauthorized access to sensitive information. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.