laradashboard vulnerability

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.

Published 7 Sep 2026Updated 7 Sep 20267 sources
CVSS 8.6

Source timeline

CVE record published by NVDView source ↗