instructure / canvas-lms

The open LMS by Instructure, Inc.
https://github.com/instructure/canvas-lms/wiki
GNU Affero General Public License v3.0
5.52k stars 2.45k forks source link

Cross Site Scripting for Canvas lms #2060

Open dubaibai1920 opened 2 years ago

dubaibai1920 commented 2 years ago

Only uploading HTML in a personal folder can lead to malicious code execution, and files can be shared in real time. Due to extensive use in the education industry, large security incidents may be triggered