cvedb.io
CVE-2025-65021
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2025-11-19T18:15:49.667 · Last modified 2026-06-17T09:55:21.453

Summary

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in the poll finalization feature of the application. Any authenticated user can finalize a poll they do not own by manipulating the pollId parameter in the request. This allows unauthorized users to finalize other users’ polls and convert them into events without proper authorization checks, potentially disrupting user workflows and causing data integrity and availability issues. This issue has been patched in version 4.5.4.

Affected products

rallly — rallly

Does this affect you?

Add your gear to cvedb and we'll alert you only when rallly ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.