LaraDashboard 1.2.2 及更早版本存在一个授权缺失漏洞,位于本地许可证(Local License)API 端点。该漏洞允许任何已认证用户读取、覆盖和删除高级模块的许可证密钥。低权限账户的攻击者可以通过访问以下端点来泄露机密许可证密钥、注入攻击者可控的值,或完全删除已存储的许可证: GET /api/admin/licenses/show POST /api/admin/licenses/store POST /api/admin/licenses/remove
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| laradashboard | laradashboard | 0 ~ 1.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90932 | 7.2 HIGH | LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE |
| CVE-2026-90931 | 5.4 MEDIUM | LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload |
No comments yet