CVE-2013-7139: Cynthia Fridsma Horizon Quick Content Management System

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter.

Affected products

  • Cynthia Fridsma Horizon Quick Content Management System: up to and including 4.0; version 3.2 only; version 3.3 only; version 3.4 only; version 3.5.1 only; version 3.5.2 only

Published 2014-01-09. Last modified 2026-06-17.