PT-2025-47501 · Rallly · Rallly

Published

2025-11-19

·

Updated

2025-11-25

·

CVE-2025-65020

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description Rallly is a scheduling and collaboration tool. An Insecure Direct Object Reference (IDOR) exists in the poll duplication endpoint /api/trpc/polls.duplicate. An authenticated user can bypass access controls by modifying the pollId parameter and duplicate polls they do not own. This allows unauthorized cloning of private or administrative polls.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

Improper Authorization

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-65020
GHSA-44W7-PF32-GV5M

Affected Products

Rallly