Ovidentia CMS 6.x contains a SQL injection vulnerability in the «id» parameter of index.php. The «checkbox» property into «text» data can be extracted and displayed in the text region or in source code.