medium · CVSS v3 5.4 · CVSS v4 5.3 · EPSS 0.0026
CVE-2026-105128
LaraDashboard versions prior to 1.4.8 are vulnerable to an open redirect via the redirect_url parameter in EmailTemplateController. This fla
Overview
LaraDashboard versions prior to 1.4.8 are vulnerable to an open redirect via the redirect_url parameter in EmailTemplateController. This flaw allows attackers to redirect authenticated users to malicious sites when they save email templates. The vulnerability can be exploited by sending crafted links to users with template permissions.
Description
LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
Impact
Confidentiality: attackers can trick users into visiting phishing sites, potentially leading to credential theft. Integrity: no direct data modification, but trust is undermined. Availability: minimal. Affected users are administrators and content editors with email template permissions.
Remediation
Upgrade to LaraDashboard 1.4.8 or later. If upgrade is not possible, validate or whitelist redirect URLs in EmailTemplateController or disable the redirect_url parameter. Monitor for suspicious email template links.
Risk context
The CVE has a medium severity (CVSS 5.4) and a low EPSS score of 0.0026, indicating a low likelihood of exploitation in the near term, but defenders should still apply the patch promptly to prevent phishing attacks.
Affected products
- LaraDashboard <1.4.8
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 5.4
- CVSS v4
- 5.3
- EPSS
- 0.0026