Impact
The vulnerability resides in the self_Tmp function of the QCMS Content Detail Page controller. By manipulating the ID argument, an attacker can inject arbitrary SQL code, which may lead to data disclosure, modification, or even deletion in the database. The issue is not a full remote code execution flaw, but it can compromise the confidentiality and integrity of the application data. The payload must contain literal spaces in the URL, as router parsing does not perform URL decoding before routing. The vulnerability can be triggered from a remote network, and the exploit has been publicly disclosed.
Affected Systems
QCMS versions up to and including 6.0.6 are affected. No specific patch or upgrade level is mentioned for these versions.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit can be performed remotely by sending a crafted REQUEST_URI that includes literal spaces, the attack vector is likely network-based. Though the official vendor response is lacking, the public disclosure indicates that exploitation is feasible with no additional prerequisites.
OpenCVE Enrichment