Impact
FineAdmin version 1.0 contains an SQL injection vulnerability that originates from the field and order parameters used by the ButtonService.GetListByFilter() endpoint. By submitting crafted SQL statements, an attacker can cause the application to execute arbitrary queries against the underlying database, potentially retrieving or manipulating sensitive application data. This flaw represents the classic SQL injection weakness defined by CWE‑89.
Affected Systems
All installations running FineAdmin version 1.0 are affected. No patch or updated version is listed in the CVE record, so any deployment that has not upgraded remains susceptible.
Risk and Exploitability
The vulnerability is not reflected in the CVSS or EPSS metrics, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the web interface or API that processes the field and order parameters; this inference is not explicitly stated in the data but is a reasonable deduction. Exploitation requires the attacker to send malicious input to the endpoint, potentially making authenticated or privileged access more effective, although the denial of such access is not explicitly required in the current description.
OpenCVE Enrichment