CVE-2026-92565
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.
Słabość
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from public invite links to retrieve sensitive invitee information regardless of privacy settings.
Źródła
- https://github.com/lukevella/rallly
- https://github.com/lukevella/rallly/blob/885bfaf4313f427a60c5349646c5b69d863750db/apps/web/src/trpc/routers/polls.ts#L568-L675
- https://github.com/lukevella/rallly/commit/0db11a2cd9e48656d08773e4be6de0e7df584a00
- https://github.com/lukevella/rallly/pull/3247
- https://github.com/lukevella/rallly/releases/tag/v4.15.0
- https://www.vulncheck.com/advisories/rallly-before-4.15.0-information-disclosure-via-polls-get
Znajdź błąd, zanim zrobi to atakujący.
Zaloguj się przez GitHub i uruchom pierwszy audyt w niecałą minutę. Plan darmowy nie wymaga karty kredytowej.