CVE-2026-105125 - LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
CVE ID :CVE-2026-105125
Published : Oct. 4, 2026, 12:16 a.m. | 6 hours, 57 minutes ago
Description :LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 4, 2026, 12:16 a.m. | 6 hours, 57 minutes ago
Description :LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...