CVE-2020-35577
Last modified
CVE-2020-35577 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file identifier (aka CommonDownload identification number).. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file identifier (aka CommonDownload identification number).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Endalia | Selection Portal | 4.205.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-35577?
How severe is CVE-2020-35577?
How do I fix CVE-2020-35577?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-35570An issue was discovered in MB connect line mymbCONNECT24, mb…5.3
- CVE-2020-35571An issue was discovered in MantisBT through 2.24.3. In the h…6.1
- CVE-2020-35572Adminer through 4.7.8 allows XSS via the history parameter t…6.1
- CVE-2020-35573srs2.c in PostSRSd before 1.10 allows remote attackers to ca…7.5
- CVE-2020-35575A password-disclosure issue in the web interface on certain …9.8
- CVE-2020-35576A Command Injection issue in the traceroute feature on TP-Li…8.8
- CVE-2020-35578An issue was discovered in the Manage Plugins page in Nagios…7.2
- CVE-2020-35579tindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=…7.5
- CVE-2020-3558A vulnerability in the web-based management interface of Cis…6.1
- CVE-2020-35580A local file inclusion vulnerability in the FileServlet in a…7.5
- CVE-2020-35581A stored cross-site scripting (XSS) issue in Envira Gallery …5.4
- CVE-2020-35582A stored cross-site scripting (XSS) issue in Envira Gallery …5.4
Are you affected by CVE-2020-35577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
