PT-2026-93810 · Rallly · Rallly
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rallly versions prior to 4.15.0
Description
An information disclosure issue exists in the
polls.get tRPC procedure. Unauthenticated callers can retrieve the names and email addresses of scheduled-event invitees by accessing a poll's urlId obtained from public invite links, bypassing established privacy settings.Recommendations
Update to version 4.15.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rallly