Medium severity6.5NVD Advisory· Published Feb 18, 2021· Updated Jun 17, 2026
CVE-2020-35577
CVE-2020-35577
Description
In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file identifier (aka CommonDownload identification number).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<4.205.0+ 1 more
- (no CPE)range: <4.205.0
- cpe:2.3:a:endalia:selection_portal:4.205.0:*:*:*:*:*:*:*
- Endalia/Selection Portaldescription
Patches
Vulnerability mechanics
References
2- github.com/blackarrowsec/advisories/tree/master/2020/CVE-2020-35577nvdThird Party Advisory
- www.endalia.com/en/software/nvdProduct
News mentions
0No linked articles in our index yet.