CVE-2026-88424: SQL Injection
FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The available information identifies the vulnerable field/order parameter in ButtonService.GetListByFilter(), but does not state whether the affected functionality requires authentication or specific permissions.
What data could be exposed through successful exploitation?
A successful SQL injection can allow an attacker to access sensitive database information through crafted SQL statements. The available information does not identify specific database tables or records.
Are versions other than FineAdmin v1.0 known to be affected?
Only FineAdmin v1.0 is identified as affected in the available information. No information is provided about other versions or a fixed release.