216.73.217.22

CVE-2025-66027

· Published 29/11/2025 01:16 · Modified 03/12/2025 20:25

Labels: CVE-2025-66027 2025-11-29CVE-2025-66027CWE-200[email protected]

Essential information

Published
29/11/2025 01:16
Modified
03/12/2025 20:25
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy features are enabled. This bypasses intended privacy controls that should prevent participants from viewing other users’ personal information. This issue has been patched in version 4.5.6.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rallly / rallly cpe:2.3:a:rallly:rallly:*:*:*:*:*:*:*:*

References