Unknown · Querymine Sms · CVE-2026-6489
**Name of the Vulnerable Software and Affected Versions**
QueryMine sms (affected versions not specified)
**Description**
An unrestricted file upload flaw exists in the Background Management Page component. The issue occurs during the processing of the file 'admin/addteacher.php' when the `image` argument is manipulated, allowing a remote attacker to upload files without restrictions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.