PT-2025-47501 · Rallly · Rallly

CVE-2025-65020

·

Published

2025-11-19

·

Updated

2025-11-25

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description Rallly is a scheduling and collaboration tool. An Insecure Direct Object Reference (IDOR) exists in the poll duplication endpoint /api/trpc/polls.duplicate. An authenticated user can bypass access controls by modifying the pollId parameter and duplicate polls they do not own. This allows unauthorized cloning of private or administrative polls.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

Improper Authorization

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65020
GHSA-44W7-PF32-GV5M

Affected Products

Rallly