LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Laradashboard
Laradashboard laradashboard |
|
| Vendors & Products |
Laradashboard
Laradashboard laradashboard |
Thu, 04 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution. | |
| Title | LaraDashboard: 1-Click Pre-Auth RCE via Host Header + Module Installation Chain | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-04T22:10:26.848Z
Updated: 2025-12-04T22:10:26.848Z
Reserved: 2025-12-03T15:12:22.978Z
Link: CVE-2025-66509
No data.
Status : Received
Published: 2025-12-04T22:15:49.673
Modified: 2025-12-04T22:15:49.673
Link: CVE-2025-66509
No data.