Impact
The vulnerability arises from the MarketplaceModuleBrowser Livewire component in Lara Dashboard. The installModule action does not enforce the ModulePolicy authorization check, permitting any authenticated administrator who is not a superadmin to trigger installation of modules. Because the marketplace can supply arbitrary PHP code, successfully invoking this action leads to remote code execution on the host.
Affected Systems
Affected versions are all releases of the laradashboard:laradashboard package prior to 1.3.2, including the 1.3.1 build. The component resides in the Livewire file MarketplaceModuleBrowser.php and the missing check is linked to ModulePolicy.php. Upgrading to version 1.3.2 or later applies the necessary authorization guard.
Risk and Exploitability
With a CVSS score of 8.6 the flaw is classified as High severity. The EPSS score is not provided, and the vulnerability has not been cataloged as a known exploited vulnerability by CISA. An attacker must be an authenticated non-superadmin administrator, which is commonly possible in most setups; through the unsigned HTTP request channel, the attacker can download and activate any module, effectively gaining remote code execution. The absence of any network barrier or additional privileges markedly increases the risk.
OpenCVE Enrichment