PT-2025-47502 · Rallly · Rallly

CVE-2025-65021

·

Publicado

2025-11-19

·

Atualizado

2025-11-25

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description An Insecure Direct Object Reference (IDOR) issue exists in the poll finalization feature of Rallly. An authenticated user can finalize a poll they do not own by manipulating the pollId parameter in the request. This allows unauthorized users to finalize other users’ polls and convert them into events without authorization checks, potentially disrupting user workflows and causing data integrity and availability issues.
Recommendations Update to version 4.5.4 or later.

Exploit

Correção

Improper Authorization

IDOR

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-65021
GHSA-X7W2-G548-4QG8

Produtos afetados

Rallly