KICS cms suffers from an SQL injection vulnerability that can be used to gain administrative privileges.