---
id: CVE-2026-94110
title: A security vulnerability has been detected in QCMS up to 6.0.6
summary: >-
  A security vulnerability has been detected in QCMS up to 6.0.6. This issue
  affects the function self_Tmp in the library Lib/Config/Controllers.php of the
  component Content Detail Page. Such manipulation of the argument ID leads to
  sql in…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
product: QCMS
affected:
  - QCMS 6.0.0
  - QCMS 6.0.1
  - QCMS 6.0.2
  - QCMS 6.0.3
  - QCMS 6.0.4
  - QCMS 6.0.5
  - QCMS 6.0.6
published: '2026-09-21'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T16:18:17.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94110'
references:
  - url: 'https://github.com/yukino06/CVE/issues/1'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94110'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/944567'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408039'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408039/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00411
epssPercentile: 0.32515
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-22T15:33:52.959046Z'
ingestedAt: '2026-09-21T02:30:07.658Z'
---

## Overview

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Router uses raw REQUEST_URI without URL decoding, so payloads must contain literal spaces - %20 never decodes before route parsing. The support team of the vendor was contacted early about this disclosure. Unfortunately, they responded just with profanity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
