medium · CVSS v3 5.3 · CVSS v4 6.9 · EPSS 0.00406
CVE-2026-105127
LaraDashboard versions 1.4.2 through 1.4.7 perform DNS lookups and external API calls during unauthenticated password‑reset requests. Attack
Overview
LaraDashboard versions 1.4.2 through 1.4.7 perform DNS lookups and external API calls during unauthenticated password‑reset requests. Attackers can abuse this to exhaust the external verification quota, causing all public reset forms to fail. The flaw also allows domain resolution probing.
Description
LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
Impact
Confidentiality: attackers can discover domain resolution information. Availability: denial of password‑reset functionality when the external verification quota is exhausted. Integrity: no direct impact. Defenders: administrators of affected LaraDashboard installations.
Remediation
Update to version 1.4.8 or later, which removes the external verification step for unauthenticated requests. If an update is not immediately possible, disable external API calls for password‑reset forms or implement rate limiting on the verification endpoint. Monitor API usage and quota consumption to detect abuse.
Risk context
The vulnerability has a medium CVSS score and a low EPSS of 0.00406, indicating a moderate risk level but a relatively low likelihood of exploitation. Prompt patching is recommended to prevent potential denial‑of‑service of password‑reset functionality.
Affected products
- LaraDashboard 1.4.2-1.4.7
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- 0.00406