CNNVD-202511-2176 Information
Nov 19, 2025
cve
CNNVD ID
CNNVD-202511-2176
Related CVE
- CNNVD Published: 2025-11-19
Description (Chinese)
Rallly是Luke Vella个人开发者的一款日程安排和协作工具,旨在更轻松地组织活动和会议。 Rallly 4.5.4之前版本存在安全漏洞,该漏洞源于参与者删除功能存在不安全的直接对象引用,可能导致未经授权的参与者删除。
Description (English)
Rollly is a calendar and collaboration tool for Luke Vella’s personal developer, which aims to organize events and meetings more easily. There was a security loophole in the previous version of Rallly 4.5.4, which stemmed from the participant ’ s failure to remove an unsafe direct reference to the function, which could lead to the removal of unauthorized participants.
Hazard Level
Medium
Vulnerability Type
其他
Affected Vendor
个人开发者
Published
2025-11-19
Last Modified
2026-02-24
References
https://github.com/lukevella/rallly/releases/tag/v4.5.4 https://github.com/lukevella/rallly/security/advisories/GHSA-f8jc-6746-ww95
Patch
https://github.com/lukevella/rallly/releases
Share on: