{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aqcmsqcms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:qcms:qcms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-94110"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["QCMS (\u003c= 6.0.6)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sqli","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["QCMS"],"content_html":"\u003cp\u003eA critical SQL injection vulnerability has been identified in QCMS versions up to 6.0.6. The flaw resides in the self_Tmp function within the file Lib/Config/Controllers.php, which handles the Content Detail Page component. Attackers can exploit this via a remote, unauthenticated request by injecting malicious SQL code into the ID argument.\u003c/p\u003e\n\u003cp\u003eDefenders should note that the QCMS router does not perform URL decoding on the incoming REQUEST_URI before routing occurs. Consequently, exploit payloads must be crafted using literal spaces rather than URL-encoded entities (like %20), as the latter are not interpreted correctly by the routing logic. This vulnerability was disclosed publicly, and given the lack of a vendor patch, organizations utilizing QCMS must implement compensating controls at the network perimeter or application firewall level to inspect and sanitize the ID parameter in incoming requests to the Content Detail Page.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to execute arbitrary SQL commands against the backend database. This may lead to unauthorized data exfiltration, modification of application content, or potential full database compromise. As the vulnerability is publicly disclosed and exploitable remotely, the risk to public-facing QCMS deployments is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy Web Application Firewall (WAF) rules to detect and block requests to the Content Detail Page containing SQL injection patterns in the ID parameter.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for the ID parameter in the application front-end or via a reverse proxy to ensure it conforms to expected alphanumeric formats.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests containing literal space characters within query strings targeting the identified path.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T02:25:36Z","date_published":"2026-09-21T02:25:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-qcms-sqli/","summary":"QCMS versions up to 6.0.6 are vulnerable to remote SQL injection via the ID argument in the self_Tmp function, allowing attackers to execute arbitrary database commands.","title":"SQL Injection Vulnerability in QCMS Content Detail Page","url":"https://feed.craftedsignal.io/briefs/2026-09-qcms-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:qcms:qcms:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}