iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.