Laradashboard

Lara Dashboard

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 03.10.2026 23:40:01
  • Zuletzt bearbeitet 05.10.2026 15:17:17

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builde...

  • EPSS 0.31%
  • Veröffentlicht 03.10.2026 23:40:01
  • Zuletzt bearbeitet 06.10.2026 17:17:17

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{o...

  • EPSS 0.31%
  • Veröffentlicht 03.10.2026 23:39:59
  • Zuletzt bearbeitet 05.10.2026 17:17:13

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to e...

  • EPSS 0.49%
  • Veröffentlicht 03.10.2026 23:39:59
  • Zuletzt bearbeitet 05.10.2026 21:16:33

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant use...

  • EPSS 0.33%
  • Veröffentlicht 09.09.2026 11:21:06
  • Zuletzt bearbeitet 09.09.2026 20:20:21

Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read interna...

  • EPSS 0.39%
  • Veröffentlicht 07.09.2026 22:17:22
  • Zuletzt bearbeitet 08.09.2026 19:56:50

Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source...

  • EPSS 0.3%
  • Veröffentlicht 07.09.2026 22:17:21
  • Zuletzt bearbeitet 09.09.2026 15:17:18

Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensio...

  • EPSS 0.6%
  • Veröffentlicht 05.09.2026 11:38:00
  • Zuletzt bearbeitet 18.09.2026 18:17:18

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screen...

  • EPSS 0.4%
  • Veröffentlicht 04.12.2025 22:10:26
  • Zuletzt bearbeitet 11.03.2026 15:58:32

LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be...