CVE-2020-35577

MEDIUM

Endalia Selection Portal <4.205.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file identifier (aka CommonDownload identification number).

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0089
EPSS Percentile 75.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
endalia/selection_portal 4.205.0
Published Feb 18, 2021
Tracked Since Feb 18, 2026