CVE-2026-6490 is a SQL injection vulnerability affecting QueryMine SMS up to commit 7ab5a9ea196209611134525ffc18de25c57d9593, specifically within the admin/deletecourse.php file's GET request parameter handler. The flaw exists in the ID parameter, which fails to properly sanitize user input before database queries. Due to QueryMine's rolling release model, specific affected version numbers are not available, complicating patch identification for end users. The vulnerability carries a HIGH severity rating of 7.3 on the CVSS scale and can be exploited remotely without authentication or user interaction required. Attack complexity is low, meaning exploitation does not require specialized conditions or techniques. The compromise could result in unauthorized data access, data modification, and potential service disruption, affecting the confidentiality, integrity, and availability of the application. Public exploit code has been released, significantly increasing the risk of active exploitation in the wild. The vulnerability is currently listed on security hotlists and requires immediate attention despite the low EPSS score. The vendor has been notified but did not respond, leaving organizations dependent on self-remediation or community-provided patches until an official update is released.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| QueryMine | Sms | 7ab5a9ea196209611134525ffc18de25c57d9593CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.