Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker to access, modify, or delete sensitive information within the database.
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-050/