A vulnerability classified as critical was found in Qcms 6.0.6. This vulnerability affects unknown code. The manipulation results in sql injection.

This vulnerability is reported as CVE-2026-67854. The attack can be launched remotely. No exploit exists.