← volver
CVE-2025-66027

Rallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy Settings

CVSS 7.1 HIGHEPSS 0.3%CWE-200CWE-284CWE-359
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
29 nov 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy features are enabled. This bypasses intended privacy controls that should prevent participants from viewing other users’ personal information. This issue has been patched in version 4.5.6.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Productos afectados
lukevella · rallly

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →