PT-2025-47511 · Rallly · Rallly

CVE-2025-65034

·

Published

2025-11-19

·

Updated

2025-11-24

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rallly versions prior to 4.5.4
Description An authorization issue exists in Rallly, a scheduling and collaboration tool. An authenticated user can manipulate the pollId parameter to reopen finalized polls owned by other users. This can disrupt event management and compromise the availability and integrity of poll data.
Recommendations Update to version 4.5.4 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65034
GHSA-5FP2-PV2J-RQPC

Affected Products

Rallly