Impact
A SQL Injection flaw exists in Siam Ordering (siam-server) 1.0.0 that allows authenticated attackers to execute arbitrary SQL commands through string concatenation using the '${}' syntax in several Mapper files, such as AdminMapper.java, MerchantWithdrawRecordMapper.java, and MemberWithdrawRecordMapper.java. The vulnerability enables malicious code execution against the underlying database, potentially exposing, altering or deleting data and compromising application integrity.
Affected Systems
The affected product is Siam Ordering (siam-server) version 1.0.0. No vendor or product alias information is available beyond the product name and version.
Risk and Exploitability
The absence of an EPSS score and CVSS rating makes precise quantification difficult, but the flaw permits remote execution of arbitrary SQL statements within a database context, which is a high‑impact outcome. Because the attack requires only authenticated access, it becomes a credible threat when legitimate users must log in to use the system. The vulnerability is not currently listed in CISA’s KEV catalog, but the potential for data breach or system compromise warrants immediate attention.
OpenCVE Enrichment