Junglewise Threat Intelligence

CVE-2026-30761: SB-MaterialAdmin SourceBans Material Admin arbitrary file upload in admin.uploadmapimg.php

CVE-2026-30761 · Severity: info · CVSS 8.8 · Published 2026-05-28

Executive brief

SourceBans Material Admin is a web-based management interface used by game server administrators to manage player bans and server configurations. A security flaw in the administrative image upload component allows an authorized user to upload malicious files to the server. If exploited, an attacker can take full control of the web server, access sensitive databases, and potentially hijack connected game servers via remote console (RCON) commands.

Technical details

An unrestricted file upload vulnerability exists in the 'pages/admin.uploadmapimg.php' component of SourceBans Material Admin. The application validates uploaded files based solely on the client-provided 'Content-Type' header, which can be easily spoofed to bypass the intended JPEG restriction. An authenticated attacker with the 'ADMIN_ADD_SERVER' permission can upload a PHP shell and a malicious '.htaccess' file into the web-accessible 'images/maps' directory. This leads to Remote Code Execution (RCE) under the context of the web server user, potentially allowing full system compromise and access to RCON credentials for connected game servers. The issue is patched in version 1.1.6 (commit fb18342).

Affected products

  • SB-MaterialAdmin SourceBans Material Admin (Web) prior to v1.1.6@fb18342

Timeline

  • 2025-10-29: disclosed: Vulnerability discovered by researcher ng-dst
  • 2025-11-12: other: Issue reported to vendor via GitHub issue #374
  • 2026-05-28: advisory: CVE-2026-30761 published

References