Another day, another 'it's not a bug, it's a feature' excuse. Sure. Because an SQL injection vulnerability is just a convenient admin feature via URL parameters.
Let's be clear: if your code behaves in ways you didn't intend—that's a bug. Even if someone claims it's 'handy'. Patch it.
P.S. Authorization 'features' are particularly special. They make a pentester's job wonderfully efficient.