PT-2025-47505 · Rallly · Rallly

Published

2025-11-19

·

Updated

2025-11-25

·

CVE-2025-65028

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description Rallly, an open-source scheduling and collaboration tool, contains a flaw where an authenticated user can change votes in polls belonging to other participants without proper authorization. The backend system uses the participantId parameter to identify votes for updates, but it does not confirm ownership or poll permissions. This allows an attacker to manipulate poll results. The API endpoint responsible for updating votes relies on the participantId parameter.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

Improper Authorization

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-65028
GHSA-PCHC-V5HG-F5GP

Affected Products

Rallly