在 LaraDashboard 版本低于 1.4.8 中存在一个权限管理不当的漏洞,该漏洞允许已认证的 Admin 用户通过编辑或重命名角色,提权为 Superadmin。具有角色编辑权限的攻击者可以将自己的角色名称更改为“Superadmin”,或授予其他用户 权限以接管账户,从而获得对核心升级和模块安装等功能的访问权限,进而实现代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| laradashboard | laradashboard | 0 ~ 1.4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105129 | 6.5 MEDIUM | LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API |
| CVE-2026-105128 | 5.4 MEDIUM | LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url |
| CVE-2026-105127 | 5.3 MEDIUM | LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints |
| CVE-2026-105125 | 3.7 LOW | LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint |
| CVE-2026-105130 | 3.7 LOW | LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit |
No comments yet