Description
A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Router uses raw REQUEST_URI without URL decoding, so payloads must contain literal spaces - %20 never decodes before route parsing. The support team of the vendor was contacted early about this disclosure. Unfortunately, they responded just with profanity.
Published: 2026-09-21
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the self_Tmp function of the QCMS Content Detail Page controller. By manipulating the ID argument, an attacker can inject arbitrary SQL code, which may lead to data disclosure, modification, or even deletion in the database. The issue is not a full remote code execution flaw, but it can compromise the confidentiality and integrity of the application data. The payload must contain literal spaces in the URL, as router parsing does not perform URL decoding before routing. The vulnerability can be triggered from a remote network, and the exploit has been publicly disclosed.

Affected Systems

QCMS versions up to and including 6.0.6 are affected. No specific patch or upgrade level is mentioned for these versions.

Risk and Exploitability

The CVSS score of 6.9 reflects a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit can be performed remotely by sending a crafted REQUEST_URI that includes literal spaces, the attack vector is likely network-based. Though the official vendor response is lacking, the public disclosure indicates that exploitation is feasible with no additional prerequisites.

Generated by OpenCVE AI on September 21, 2026 at 02:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update QCMS to the newest available version that contains the fix for the self_Tmp SQL injection, if such a version exists.
  • Modify the source code in Lib/Config/Controllers.php to validate the ID parameter and use parameterized queries or proper escaping to eliminate the injection point.
  • Adjust the web server or framework routing logic to decode or reject URIs containing literal spaces before processing, or enforce strict URL decoding.
  • As an interim workaround, block or tightly filter requests that reach the Content Detail Controller or strip literal spaces from the REQUEST_URI before it is processed.

Generated by OpenCVE AI on September 21, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Router uses raw REQUEST_URI without URL decoding, so payloads must contain literal spaces - %20 never decodes before route parsing. The support team of the vendor was contacted early about this disclosure. Unfortunately, they responded just with profanity.
Title QCMS Content Detail Controllers.php self_Tmp sql injection
First Time appeared Qcms
Qcms qcms
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:qcms:qcms:*:*:*:*:*:*:*:*
Vendors & Products Qcms
Qcms qcms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:41:40.199Z

Reserved: 2026-09-20T11:29:48.456Z

Link: CVE-2026-94110

cve-icon Vulnrichment

Updated: 2026-09-22T15:33:53.956Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T02:16:53.853

Modified: 2026-09-22T16:18:17.327

Link: CVE-2026-94110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')