CVE-2025-65028 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenti…
Medium CVSS: 6.5

CVE-2025-65028

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenticated user to modify other participants’ votes in polls without authorization. The backend relies solely on the participantId parameter to identify which votes to update, without verifying ownership or poll permissions. This allows an attacker to alter poll results in their favor, directly compromising data integrity. This issue has been patched in version 4.5.4.
Vendor
Rallly
Product
Rallly
CWE
CWE-285
Yayın Tarihi
2025-11-19 18:15:50
Güncelleme
2025-11-25 15:32:31
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar