Sefrengo CMS 1.6.0 SQL Injection

Sefrengo CMS version 1.6.0 suffers from a remote SQL injection in the administrative backend.