CVE-2026-30760 Details
Description
An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.
A SQL injection vulnerability has been identified in SourceBans Material Admin versions prior to 1.1.6, specifically in the ChangeAdminsInfos endpoint. This vulnerability allows authenticated attackers to manipulate user data by injecting malicious payloads into profile link fields. The injection exploits a flaw in how user input is sanitized, leading to unauthorized modifications of admin credentials and privileges. Additionally, the absence of CSRF protection on this endpoint enables a one-click account takeover by chaining a cross-site request forgery with the SQL injection.
Update SourceBans Material Admin to version 1.1.6 or later. If an immediate update is not possible, temporarily disable the ChangeAdminsInfos endpoint or apply a manual patch to remove the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/ng-dst/450b698433f628990921f1e5ab46ff8c | [email protected] | ExploitTechnical Description |
| https://gist.github.com/ng-dst/ca6663a4107fd39eaba1be2cb1d52b51 | [email protected] | ExploitTechnical Analysis |
| https://github.com/SB-MaterialAdmin/Web | [email protected] | ProductVendor |
| https://github.com/SB-MaterialAdmin/Web/issues/374 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SourceBans Material Admin | < 1.1.6 (3ecd95e) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | New CVE Received | [email protected] |
Volerion