Lara Dashboard 1.3.2 之前的版本未能对 MarketplaceModuleBrowser 的 installModule Livewire 操作进行授权,允许非 Superadmin 的管理员安装模块。攻击者可以通过未签名的 HTTP 请求从市场下载并自动激活任意 PHP 模块,从而实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| laradashboard | laradashboard | 0 ~ 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86437 | 7.2 HIGH | Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload |
| CVE-2026-86436 | 5.4 MEDIUM | Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints |
No comments yet