Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the poll duplication endpoint (/api/trpc/polls.duplicate) allows any authenticated user to duplicate polls they do not own by modifying the pollId parameter. This effectively bypasses access control and lets unauthorized users clone private or administrative polls. This issue has been patched in version 4.5.4.
References
Configurations
No configuration.
History
19 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 18:15
Updated : 2025-11-19 19:14
NVD link : CVE-2025-65020
Mitre link : CVE-2025-65020
CVE.ORG link : CVE-2025-65020
JSON object : View
Products Affected
No product.
