CVE-2026-30760
An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.
More information : https://gist.github.com/ng-dst/450b698433f628990921f1e5ab46ff8c
