PT-2025-47509 · Rallly · Rallly

CVE-2025-65032

·

Published

2025-11-19

·

Updated

2025-11-20

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description Rallly is a scheduling and collaboration tool. A security issue exists where an authenticated user can modify the display names of other participants in polls without authorization. This is possible by manipulating the participantId parameter in a rename request. This can lead to data integrity issues and potential impersonation.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65032
GHSA-Q9M7-CHFX-43XW

Affected Products

Rallly