SQL Injection vulnerability in SEMCMS v.4.8 allows a remote malicious user to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.