|Release Date:||2011-11-17 (Last update can be found below the document title)|
|Description:||SQL Sanitization Vulnerability|
|Criticality Level:||Highly Critical ( Less Critical < Critical < Moderately Critical < Highly Critical )|
|Systems Affected:||Canvas LMS|
|Discovered By:||Securus Global|
A security audit has identified a SQL injection attack vector in the file re-ordering capability, available in the users file area and the course/group file areas.
A fix to properly escape the posted user input has been developed and deployed to Canvas Cloud. Users of Canvas CV are encouraged to either update to the most recent stable code or apply the patch manually immediately.