在 Lara Dashboard 1.3.2 之前, 端点仅使用 权限进行鉴权,使得非超级管理员(non-Superadmin)的管理员也能上传并解压任意 ZIP 压缩包,直接覆盖到正在运行的应用程序源代码之上。攻击者可以上传一个包含被修改的应用程序文件(如 )的恶意压缩包,这些文件中嵌入了系统命令,该命令将以 Web 服务器用户的身份执行,从而能够访问环境变量中的密钥和数据库凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| laradashboard | laradashboard | 0 ~ 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86438 | 7.2 HIGH | Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action |
| CVE-2026-86436 | 5.4 MEDIUM | Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints |
No comments yet