CVE-2026-30761 Details
Description
An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.
A vulnerability allowing arbitrary file upload has been identified in SourceBans Material Admin version 1.1.6 prior to 1.1.6@fb18342. This vulnerability exists in the 'pages/admin.uploadmapimg.php' component, where the upload handler only checks the file's reported Content-Type and PHP upload error code. This allows authenticated attackers with the ADMIN_ADD_SERVER flag to bypass the Content-Type validation and upload malicious files, such as PHP shells, which can be executed on the server.
Users are advised to update SourceBans Material Admin to the latest version. If an immediate update is not possible, the 'admin.uploadmapimg.php' page can be temporarily disabled or patched manually.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/ng-dst/254163056c2d8a2f55259dcb79531b31 | [email protected] | ExploitTechnical Description |
| https://gist.github.com/ng-dst/ca6663a4107fd39eaba1be2cb1d52b51 | [email protected] | ExploitTechnical Analysis |
| https://github.com/SB-MaterialAdmin/Web | [email protected] | ProductVendor |
| https://github.com/SB-MaterialAdmin/Web/issues/374 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SourceBans Material Admin | < 1.1.6@fb18342 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | New CVE Received | [email protected] |
Volerion