HIGH🇵🇱 Wersja polska

CVE-2025-66027

CVSS 7.1v4.0pub. 2025-11-29upd. 2025-12-03

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy features are enabled. This bypasses intended privacy controls that should prevent participants from viewing other users’ personal information. This issue has been patched in version 4.5.6.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Rallly

    APP
    Rallly
    < 4.5.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-65021CRITICAL9.1PL ✓same product

IDOR w Rallly — nieautoryzowane finalizowanie ankiet innych użytkowników

CVE-2025-47781CRITICAL9.8PL ✓same product

Rallly – brute force tokenu logowania umożliwia przejęcie konta

CVE-2025-65034HIGH8.1same product

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization ...

CVE-2025-65029HIGH8.1same product

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object ...

CVE-2025-65030HIGH7.1same product

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in t...