CyberRota Analysis
AI-GeneratedQcms version 6.0.6 is vulnerable to an SQL Injection flaw that enables remote attackers to execute arbitrary code on the affected system. Organizations using this version of Qcms should prioritize remediation efforts to mitigate potential unauthorized access and control over their databases. Immediate action is recommended for those managing sensitive data or critical applications reliant on this software.
CVE
CVE-2026-67854
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%
Original NVD Description
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code