CVE-2025-65021 is an Insecure Direct Object Reference (IDOR) vulnerability in Rallly versions prior to 4.5.4, allowing any authenticated user to finalize polls they do not own by manipulating the pollId parameter. This critical vulnerability (CVSS 9.1) has a low attack complexity and can lead to significant data integrity and availability issues by disrupting user workflows. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness among security researchers. Organizations using Rallly should upgrade to version 4.5.4 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.4CPE matchmatch criteria | cpe:2.3:a:rallly:rallly:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.