Impact
The vulnerability resides in the pages/admin.uploadmapimg.php script of SourceBans Material Admin v1.1.6. An attacker can upload a specially crafted image file that is not properly validated, allowing execution of arbitrary code on the host. This flaw provides remote code execution, potentially granting full system compromise and access to sensitive data.
Affected Systems
The affected product is SourceBans Material Admin, version 1.1.6, specifically the admin.uploadmapimg.php component. No other vendors or versions are listed, and the vulnerability is not registered by a CNA.
Risk and Exploitability
The CVSS score is 7.3, indicating high severity. The EPSS score is 0.00018, which is less than 1%, and the issue is not listed in the CISA KEV catalog, the lack of validation enables a direct exploitation path. The likely attack vector is uploading a malicious image through the web interface that is processed and executed on the server. Successful exploitation requires the attacker to reach the upload endpoint, typically an authenticated administrator, and to supply a file that bypasses the application’s checks.
OpenCVE Enrichment