An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary code execution via crafted image upload in SourceBans Material Admin 1.1.6 |
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 28 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary code execution via crafted image upload in SourceBans Material Admin 1.1.6 | |
| Weaknesses | CWE-434 |
Thu, 28 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-28T00:00:00.000Z
Updated: 2026-05-29T15:56:03.708Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30761
Updated: 2026-05-29T15:55:58.056Z
Status : Deferred
Published: 2026-05-28T19:16:37.360
Modified: 2026-05-29T16:16:24.940
Link: CVE-2026-30761
No data.