PT-2026-96030 · Qcms · Qcms

·

CVE-2026-94110

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QCMS versions prior to 6.0.7
Description A remote SQL injection exists in the Content Detail Page component within the self Tmp() function located in the Lib/Config/Controllers.php library. The issue occurs when the ID argument is manipulated. Additionally, the router utilizes the raw REQUEST URI without URL decoding, meaning payloads must contain literal spaces because %20 is not decoded before route parsing.
Recommendations Update QCMS to a version newer than 6.0.6. As a temporary mitigation, restrict access to the self Tmp() function in the Lib/Config/Controllers.php library.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94110

Affected Products

Qcms