r/cybersecurity 🔐 Cybersecurity 👁 0

Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable".

Could show a ton of screenshots but this one sums it up https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs It showed enough PII from everyone in my course that it would have been cake to privilege esc

📄

This source provides headlines only. Use the button below to read the complete article on the original site.

📰 Read the original article on r/cybersecurity

Originally published by r/cybersecurity. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.