Unrated severityNVD Advisory· Published Feb 18, 2021· Updated Aug 4, 2024
CVE-2020-35577
CVE-2020-35577
Description
In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file identifier (aka CommonDownload identification number).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Endalia/Selection Portaldescription
- Range: <4.205.0
Patches
Vulnerability mechanics
References
2- github.com/blackarrowsec/advisories/tree/master/2020/CVE-2020-35577mitrex_refsource_MISC
- www.endalia.com/en/software/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.