PT-2025-47505 · Rallly · Rallly

CVE-2025-65028

·

Publicado

2025-11-19

·

Atualizado

2025-11-25

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description Rallly, an open-source scheduling and collaboration tool, contains a flaw where an authenticated user can change votes in polls belonging to other participants without proper authorization. The backend system uses the participantId parameter to identify votes for updates, but it does not confirm ownership or poll permissions. This allows an attacker to manipulate poll results. The API endpoint responsible for updating votes relies on the participantId parameter.
Recommendations Update to version 4.5.4 or later.

Exploit

Correção

Improper Authorization

IDOR

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-65028
GHSA-PCHC-V5HG-F5GP

Produtos afetados

Rallly