PT-2026-104594 · Unknown · Laradashboard

·

CVE-2026-105128

·

Published

2026-10-03

·

Updated

2026-10-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LaraDashboard versions prior to 1.4.8
Description An open redirect issue exists where remote attackers can redirect users to external phishing sites. This occurs when an unvalidated redirect url parameter is supplied to the builder and builderEdit endpoints of the EmailTemplateController. Logged-in users with email template permissions may be affected if they interact with crafted builder links and save a template.
Recommendations Update to version 1.4.8 or later. As a temporary mitigation, restrict access to the builder and builderEdit endpoints of the EmailTemplateController or avoid using the redirect url parameter.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105128
GHSA-J2VP-W788-8FCF

Affected Products

Laradashboard