CVE Explorer
CVE-2025-65033
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any authenticated user to pause or resume any poll, regardless of ownership. The system only uses the public pollId to identify polls, and it does not verify whether the user performing the action is the poll owner. As a result, any user can disrupt polls created by others, leading to a loss of integrity and availability across the application. This issu
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"rallly","vendor":"lukevella","versions":[{"status":"affected","version":"< 4.5.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/lukevella/rallly/releases/tag/v4.5.4","tags":["x_refsource_MISC"],"url":"https://github.com/lukevella/rallly/releases/tag/v4.5.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/lukevella/rallly/security/advisories/GHSA-4p93-v53r-vch3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/adp/0/references/0
{"name":"https://github.com/lukevella/rallly/security/advisories/GHSA-4p93-v53r-vch3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lukevella/rallly/security/advisories/GHSA-4p93-v53r-vch3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1b1812fcfa66996a72d87003f876d1dfdbdeea5359b5530851f01ffc1b1a3cd0 · sha256:d1c29593e8f31dad… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.