Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-71808

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Sep 09, 2026
Vendor unknown

Description

A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java).

References