NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.
- https://www.exploit-db.com/exploits/44911/
No PoCs found on GitHub currently.