HIGH🇵🇱 Wersja polska

CVE-2025-65030

CVSS 7.1v3.1pub. 2025-11-19upd. 2025-11-25

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment deletion API allows any authenticated user to delete comments belonging to other users, including poll owners and administrators. The endpoint relies solely on the comment ID for deletion and does not validate whether the requesting user owns the comment or has permission to remove it. This issue has been patched in version 4.5.4.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
  • Rallly

    APP
    Rallly
    < 4.5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-65021CRITICAL9.1PL ✓same product

IDOR w Rallly — nieautoryzowane finalizowanie ankiet innych użytkowników

CVE-2025-47781CRITICAL9.8PL ✓same product

Rallly – brute force tokenu logowania umożliwia przejęcie konta

CVE-2025-66027HIGH7.1same product

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure ...

CVE-2025-65033HIGH8.1same product

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in t...

CVE-2025-65034HIGH8.1same product

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization ...