← Retour
Web Application
CVE-2026-86438 high CVSS 7.2

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-ac...

Résumé

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code...

Résumé IA openai / gpt-4o

Lara Dashboardのバージョン1.3.2以前では、非Superadminの管理者がモジュールをインストールできるという問題がありました。これにより、攻撃者は署名されていないHTTPリクエストを介して悪意のあるPHPモジュールをダウンロードし、自動的にアクティブ化することが可能です。この脆弱性はリモートコード実行を許し、高いリスクがあります。
❓ Quel est le problème
非Superadminの管理者がモジュールをインストールできる認可不足の問題。
📍 Périmètre concerné
Lara Dashboardのバージョン1.3.2以前。
🔥 Gravité
この問題により、攻撃者がリモートで任意のコードを実行できるため、高リスクである。
🔧 Comment corriger
バージョン1.3.2にアップデートすることで修正される。
🛡️ Contournement
Superadmin以外の管理者からのモジュールインストールを一時的に制限する。
🔍 Détection
システムログとインストールされたモジュールの確認を行い、不正なインストールがないかチェックする。

Références

🍪 À propos des cookies

Nous utilisons des cookies pour conserver votre session, mémoriser la langue et améliorer le service.

En savoir plus →