A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java).
References
History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote Authenticated SQL Injection in Siam Ordering Server 1.0.0
Weaknesses CWE-89

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java).
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-09-09T00:00:00.000Z

Updated: 2026-09-09T20:36:08.554Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71808

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T21:17:03.813

Modified: 2026-09-09T21:17:03.813

Link: CVE-2026-71808

cve-icon Redhat

No data.