SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserModel.php component.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.