CVE-2025-65029
HIGHrallly < 4.5.4 - Authenticated Insecure Direct Object Reference in Participant Deletion Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-65029. PoCs published by alaeddine03.
AI-analyzed exploit summary This repository provides a detailed description of CVE-2025-65029, an Insecure Direct Object Reference (IDOR) vulnerability in Rallly. The vulnerability allows authenticated users to delete arbitrary participants from polls without proper ownership verification, impacting data integrity and availability.
Description
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenticated user to delete arbitrary participants from polls without ownership verification. The endpoint relies solely on a participant ID to authorize deletions, enabling attackers to remove other users (including poll owners) from polls. This impacts the integrity and availability of poll participation data. This issue has been patched in version 4.5.4.
Exploits (1)
This repository provides a detailed description of CVE-2025-65029, an Insecure Direct Object Reference (IDOR) vulnerability in Rallly. The vulnerability allows authenticated users to delete arbitrary participants from polls without proper ownership verification, impacting data integrity and availability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H