Description
FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Assess Impact
AI Analysis

Impact

FineAdmin version 1.0 contains an SQL injection vulnerability that originates from the field and order parameters used by the ButtonService.GetListByFilter() endpoint. By submitting crafted SQL statements, an attacker can cause the application to execute arbitrary queries against the underlying database, potentially retrieving or manipulating sensitive application data. This flaw represents the classic SQL injection weakness defined by CWE‑89.

Affected Systems

All installations running FineAdmin version 1.0 are affected. No patch or updated version is listed in the CVE record, so any deployment that has not upgraded remains susceptible.

Risk and Exploitability

The vulnerability is not reflected in the CVSS or EPSS metrics, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the web interface or API that processes the field and order parameters; this inference is not explicitly stated in the data but is a reasonable deduction. Exploitation requires the attacker to send malicious input to the endpoint, potentially making authenticated or privileged access more effective, although the denial of such access is not explicitly required in the current description.

Generated by OpenCVE AI on October 5, 2026 at 20:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FineAdmin to a version that addresses the SQL injection flaw.
  • If a patch is not yet available, enforce input validation on the field and order parameters, allowing only a predefined set of values.
  • Configure the database account used by FineAdmin with the least privileges necessary to limit potential data exposure.
  • Monitor application logs for attempts to inject SQL statements to detect ongoing attacks.

Generated by OpenCVE AI on October 5, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Title FineAdmin v1.0 SQL Injection via Field/Order Parameter
Weaknesses CWE-89

Mon, 05 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T18:19:43.170Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:26.053

Modified: 2026-10-05T19:17:26.053

Link: CVE-2026-88424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:21Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')