Sapid CMS contains a flaw that may allow a malicious user to upload files or images without being authenticated. The issue is caused due to missing access control on the "usr/system/insert_file.php", "usr/system/insert_image.php", "usr/system/insert_link.php", "usr/system/insert_qcfile.php", and "usr/system/edit.php" scripts.