CPE
QCMS versions up to 6.0.6 are vulnerable to remote SQL injection via the ID argument in the self_Tmp function, allowing attackers to execute arbitrary database commands.