LaraDashboard 从 0.9.0 到 1.2.2 版本在媒体上传过程中未对 SVG 文件内容进行有效净化,使得仅拥有 权限的已认证用户可以上传包含 标签的恶意 SVG 文件。当任何用户(包括管理员)打开由应用源站直接内联返回的已存储 SVG 文件时,其中嵌入的 JavaScript 代码将在仪表盘上下文中执行,从而导致会话劫持和通过接管管理员账号进行权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| laradashboard | laradashboard | 0.9.0 ~ 1.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90932 | 7.2 HIGH | LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE |
| CVE-2026-90933 | 7.1 HIGH | laradashboard through 1.2.2 Missing Authorization via License API |
No comments yet