CVE-2025-66509 | LaraDashboard up to 2.3.0 Header ServiceProvider::boot Host access control (GHSA-j9mm-c9cj-pc82)
A vulnerability was found in LaraDashboard up to 2.3.0. It has been declared as critical. This issue affects the function ServiceProvider::boot of the component Header Handler. Such manipulation of the argument Host leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-66509. The attack can be launched remotely. No exploit exists.
It is best practice to apply a patch to resolve this issue.