PT-2025-47511 · Rallly · Rallly

Published

2025-11-19

·

Updated

2025-11-24

·

CVE-2025-65034

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description An authorization issue exists in Rallly, a scheduling and collaboration tool. An authenticated user can manipulate the pollId parameter to reopen finalized polls owned by other users. This can disrupt event management and compromise the availability and integrity of poll data.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-65034
GHSA-5FP2-PV2J-RQPC

Affected Products

Rallly