CyberRota Analysis
AI-GeneratedLaraDashboard versions prior to 1.4.8 are vulnerable due to improper privilege management, enabling authenticated Admin users to escalate their privileges to Superadmin by editing or renaming roles. This flaw allows attackers with role.edit permissions to assume Superadmin status or gain access to user accounts, potentially leading to unauthorized code execution through core upgrades and module installations. Organizations using LaraDashboard should prioritize patching this vulnerability to mitigate the risk of privilege escalation and account takeover.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.