Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5775

26
FAUCET Score

CVE-2020-5775 describes a Server-Side Request Forgery (SSRF) vulnerability in Canvas LMS version 2020-07-29, allowing an unauthenticated attacker to force the application to make HTTP GET requests to arbitrary domains. This medium-severity vulnerability has a CVSS score of 5.8, indicating low attack complexity and impact, with no confidentiality or availability impact but potential for integrity compromise. While there is no evidence of active exploitation or public exploit code like Metasploit or ExploitDB, a Nuclei template exists for detection. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
2020-07-29CPE matchmatch criteria
cpe:2.3:a:instructure:canvas_learning_management_service:2020-07-29:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.8MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.53%
Probability of exploitation in next 30 days
EPSS Percentile
93.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Nuclei: CVE-2020-5775 · Nov 24, 2021
This CVE's current EPSS score of 0.0653 is in the 90th percentile among its peer group of 23,701 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (7)

esetvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
mariadbvendor investigatingvia llm_extracted
omronvendor investigatingvia llm_extracted
openrefinevendor investigatingvia llm_extracted
pnpmvendor investigatingvia llm_extracted
twiliovendor investigatingvia llm_extracted

Vendor Advisories (7)

twiliollm-twilio-fb5131e501d7fe8cMEDIUM

Canvas LMS Unauthenticated Blind SSRF

Aug 11, 2020
esetllm-eset-fe5af845915fa35cMEDIUM

Canvas LMS Unauthenticated Blind SSRF

Aug 11, 2020
hyperledgerllm-hyperledger-e1ac5b00b6c8bdf2MEDIUM

Canvas LMS Unauthenticated Blind SSRF

Aug 11, 2020
pnpmllm-pnpm-dcce2c6aae2da7d4MEDIUM

Canvas LMS Unauthenticated Blind SSRF

Aug 11, 2020
omronllm-omron-8326ea5e8d16acb5MEDIUM

Canvas LMS Unauthenticated Blind SSRF

Aug 11, 2020
openrefinellm-openrefine-a57451a3f3792406MEDIUM

Canvas LMS Unauthenticated Blind SSRF

Aug 11, 2020
mariadbllm-mariadb-11dea075abd7d74bMEDIUM

Canvas LMS Unauthenticated Blind SSRF

Aug 11, 2020

References

tenable.com / security/research/tra-2020-49
ExploitPatchThird Party Advisory