Key Information Vulnerability Type SQL Injection Vulnerability Location The method in the code contains an injection point, specifically in the handling of the parameter. Vulnerable Code Snippet Controller Code Payload HTTP Request Example Additional Information The interface lacks permission checks, making it vulnerable to injection attacks.