LaraDashboard 版本 0.9.2 至 1.2.2 在核心升级备份处理中存在路径遍历(Path Traversal)漏洞。具体而言, 和 (例如 )将用户提供的 / 值直接拼接至备份目录路径,未进行路径规范化,未使用 ,也未校验解析后的路径是否仍位于 目录内;相应的表单请求仅将该值作为有界字符串进行校验。 仅持有 委托权限(而非 Superadmin)的已认证用户,可通过输入包含 的遍历序列,删除主机文件系统中可达的任意文件(包括应用目录树之外的文件),或从磁盘上的任意位置恢复 ZIP 压缩包,从而将任意
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| laradashboard | laradashboard | 0.9.2 ~ 1.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90933 | 7.1 HIGH | laradashboard through 1.2.2 Missing Authorization via License API |
| CVE-2026-90931 | 5.4 MEDIUM | LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload |
No comments yet