.. / CVE-2020-5775

Exploit for Canvas LMS v2020-07-29 - Blind Server-Side Request Forgery (CVE-2020-5775)

Description:

Canvas version 2020-07-29 is susceptible to blind server-side request forgery. An attacker can cause Canvas to perform HTTP GET requests to arbitrary domains and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2020-5775.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-5775.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://github.com/ARPSyndicate/kenzer-templates
https://www.tenable.com/security/research/tra-2020-49
https://nvd.nist.gov/vuln/detail/CVE-2020-5775