FinancialService::getMemberByScanString. This manipulation of the argument routeAndAccount causes sql injection.This vulnerability is handled as CVE-2026-40482. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
SOCIAL SHARE CARD GENERATOR