Impact
Rallly before version 4.15.0 exposes the names and email addresses of poll invitees through the polls.get tRPC procedure to anyone who can call it. The vulnerability allows an unauthenticated attendee to enumerate sensitive personal data regardless of the poll’s privacy settings, effectively leaking personally identifying information to external observers.
Affected Systems
All installations of Rallly produced by lukevella before release 4.15.0 are affected. Users who are running any pre‑4.15.0 version of the application are at risk if they expose poll URLs or allow public invite links.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity with potential confidentiality impact. The EPSS score is below 1%, suggesting a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can obtain a poll’s identifier from public invite links and then invoke polls.get without authentication. The exploitation requires only a simple HTTP request to the exposed endpoint, with no privileged access or complex prerequisites.
OpenCVE Enrichment