rootpwn

medium · CVSS v3 5.3 · CVSS v4 6.9 · EPSS 0.00406

CVE-2026-105127

LaraDashboard versions 1.4.2 through 1.4.7 perform DNS lookups and external API calls during unauthenticated password‑reset requests. Attack

Overview

LaraDashboard versions 1.4.2 through 1.4.7 perform DNS lookups and external API calls during unauthenticated password‑reset requests. Attackers can abuse this to exhaust the external verification quota, causing all public reset forms to fail. The flaw also allows domain resolution probing.

Description

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.

Impact

Confidentiality: attackers can discover domain resolution information. Availability: denial of password‑reset functionality when the external verification quota is exhausted. Integrity: no direct impact. Defenders: administrators of affected LaraDashboard installations.

Remediation

Update to version 1.4.8 or later, which removes the external verification step for unauthenticated requests. If an update is not immediately possible, disable external API calls for password‑reset forms or implement rate limiting on the verification endpoint. Monitor API usage and quota consumption to detect abuse.

Risk context

The vulnerability has a medium CVSS score and a low EPSS of 0.00406, indicating a moderate risk level but a relatively low likelihood of exploitation. Prompt patching is recommended to prevent potential denial‑of‑service of password‑reset functionality.

Affected products

  • LaraDashboard 1.4.2-1.4.7

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
6.9
EPSS
0.00406

password-reset DNS-lookup API-exhaustion availability LaraDashboard medium-severity

← All CVEs