Sceawere

Vulnerability Detail

CVE-2026-105128UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LaraDashboard Open Redirect Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
laradashboard
Product
laradashboard
Attack Type
URL Redirection to Untrusted Site ('Open Redirect')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-04T00:16:36.563Z",
  "pubdate": "2026-10-04T00:16:36.563Z",
  "executiveSummary": "LaraDashboard versions prior to 1.4.8 are susceptible to an open redirect vulnerability located within the EmailTemplateController.\nThis vulnerability is classified as an improper neutralization of input during web page generation, enabling attackers to facilitate phishing campaigns by manipulating redirect behavior.\nThe flaw allows an unauthenticated or remote attacker to craft malicious URLs that leverage the application's internal redirect mechanisms to steer legitimate, logged-in users toward arbitrary, attacker-controlled domains.\nSuccessful exploitation requires the victim to possess specific email template permissions and requires the victim to interact with a crafted link, typically delivered via social engineering.\nThe risk implication is significant as it facilitates credential harvesting, malware distribution, or further exploitation by leveraging the perceived trust of the legitimate LaraDashboard application domain.\nThe vulnerability manifests due to the lack of validation on the 'redirect_url' parameter when interacting with template building functions.",
  "technicalDetails": "The vulnerability resides in the 'EmailTemplateController', specifically within the 'builder' and 'builderEdit' methods. The root cause is the insecure implementation of redirection logic that relies on user-supplied input without appropriate sanitization, validation, or allowlisting of the destination URL provided via the 'redirect_url' query parameter.\nIn the context of the 'builder' and 'builderEdit' functions, the application accepts the 'redirect_url' input and incorporates it directly into a redirect response without verifying if the target destination belongs to an authorized or expected domain. This pattern constitutes a classic open redirect flaw.\nThe attack flow begins when an attacker crafts a malicious URL pointing to the vulnerable LaraDashboard endpoint, appending a payload to the 'redirect_url' parameter (e.g., https://victim-laredashboard.com/email-template/builder?redirect_url=https://attacker-controlled-phishing-site.com).\nTo maximize impact, the attacker transmits this crafted link to a victim who is currently authenticated to the LaraDashboard instance and possesses sufficient privileges, specifically 'email template' administrative permissions. Upon the victim clicking the link, the application processes the request, performs the internal logic, and subsequently issues an HTTP 302 redirect to the attacker-supplied URL.\nThe primary risk is phishing; because the redirect originates from a trusted, authenticated application domain, users are significantly more likely to trust the subsequent destination. This allows attackers to perform transparent credential harvesting or deliver malicious payloads under the guise of an authenticated session.\nThe vulnerability is exposed via the web interface and does not require elevated privileges on the server side to trigger; however, the successful completion of the redirection process requires the victim to be authenticated to the platform to reach the controller's logic.\nThe vulnerability affects all versions of LaraDashboard prior to 1.4.8. Post-exploitation impact is limited to the redirection of the user; however, in the broader context of an attack chain, this represents a critical component of a larger social engineering or cross-site scripting (XSS) delivery vector."
}
CVE-2026-105128: LaraDashboard Open Redirect Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere