PT-2025-47502 · Rallly · Rallly

Published

2025-11-19

·

Updated

2025-11-25

·

CVE-2025-65021

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description An Insecure Direct Object Reference (IDOR) issue exists in the poll finalization feature of Rallly. An authenticated user can finalize a poll they do not own by manipulating the pollId parameter in the request. This allows unauthorized users to finalize other users’ polls and convert them into events without authorization checks, potentially disrupting user workflows and causing data integrity and availability issues.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

Improper Authorization

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-65021
GHSA-X7W2-G548-4QG8

Affected Products

Rallly