CVE-2026-105128

Summary

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.

Affected Software

VendorProductVersion RangeStatus
laradashboardlaradashboard0 < 1.4.8affected
laradashboardlaradashboard1.4.8unaffected

Weaknesses

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

References