GHSA-4h8m-c92p-4pmvMediumCVSS 5.4

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers...

Published
October 4, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (1)

📋 Description

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.

🔗 References (11)