VYPR
Unrated severityNVD Advisory· Published Nov 19, 2025· Updated Nov 19, 2025

Rallly Improper Authorization in Comment Endpoint Allows User Impersonation

CVE-2025-65031

Description

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint allows authenticated users to impersonate any other user by altering the authorName field in the API request. This enables attackers to post comments under arbitrary usernames, including privileged ones such as administrators, potentially misleading other users and enabling phishing or social engineering attacks. This issue has been patched in version 4.5.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Lukevella/Ralllyllm-fuzzy2 versions
    <4.5.4+ 1 more
    • (no CPE)range: <4.5.4
    • (no CPE)range: < 4.5.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.