CVE-2021-36539
26.01.2023, 21:15
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).Enginsight
Vendor | Product | Version |
---|---|---|
instructure | canvas_learning_management_service | 𝑥 < 2022-10-15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration