CVE-2026-105128: LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url
LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirecturl parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this redirect attack?
Logged-in users who have permission to work with email templates are the target. An attacker can send those users a crafted Email Template Builder link and rely on them saving a template.
What interaction is required for exploitation?
The attacker needs to supply an unvalidated redirect_url value in a crafted link and persuade a permitted, logged-in user to use it and save a template. No attacker authentication or special privileges are indicated.
Are installations running version 1.4.8 or later affected?
The issue is described as affecting LaraDashboard versions before 1.4.8. The provided data does not identify any affected versions beyond that range.