Impact
A flaw in Siam Ordering (siam-server) 1.0.0 allows authenticated attackers to inject arbitrary SQL commands through string concatenation using the '${}' syntax in several Mapper files, including AdminMapper.java, MerchantWithdrawRecordMapper.java, and MemberWithdrawRecordMapper.java. The vulnerability permits execution of malicious SQL statements against the underlying database, potentially exposing, modifying, or deleting data. This can compromise data confidentiality, integrity, and the overall reliability of the application.
Affected Systems
The affected product is Siam Ordering (siam-server) version 1.0.0. No other vendor or product variants are referenced in the CVE data.
Risk and Exploitability
8.8 indicates a high‑impact vulnerability, while the EPSS score of < 1 % suggests exploitation is unlikely but possible. Because the flaw requires authenticated access, the vulnerability is not listed in CISA’s KEV catalog, but the ability to alter or exfiltrate database contents warrants full attention. Attackers would exploit the injection via application endpoints that construct SQL queries with untrusted input, leading to data compromise or denial of service.
OpenCVE Enrichment