GHSA-m6xm-3prx-hrjpMediumCVSS 3.7

LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in...

Published
October 4, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (1)

📋 Description

LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.

🔗 References (10)