PT-2025-47508 · Rallly · Rallly

Published

2025-11-19

·

Updated

2025-11-25

·

CVE-2025-65031

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description Rallly, an open-source scheduling and collaboration tool, contains a flaw in authorization related to comment creation. An authenticated user can impersonate any other user by modifying the authorName field within an API request. This allows attackers to post comments attributed to arbitrary usernames, including those with administrative privileges, potentially leading to phishing or social engineering attacks. The vulnerable endpoint is the comment creation API.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

Improper Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-65031
GHSA-HHFC-6GQ7-RRPM

Affected Products

Rallly