Vulnerabilities > CVE-2020-35577 - Unspecified vulnerability in Endalia Selection Portal 4.205.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file identifier (aka CommonDownload identification number).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |