PT-2026-104594 · Unknown · Laradashboard
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LaraDashboard versions prior to 1.4.8
Description
An open redirect issue exists where remote attackers can redirect users to external phishing sites. This occurs when an unvalidated
redirect url parameter is supplied to the builder and builderEdit endpoints of the EmailTemplateController. Logged-in users with email template permissions may be affected if they interact with crafted builder links and save a template.Recommendations
Update to version 1.4.8 or later.
As a temporary mitigation, restrict access to the
builder and builderEdit endpoints of the EmailTemplateController or avoid using the redirect url parameter.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laradashboard