A vulnerability labeled as critical has been found in code-projects Web-Based Inventory and POS System 1.0. This impacts an unknown function of the file /login.php. Executing manipulation of the argument emailid can lead to sql injection.
This vulnerability appears as CVE-2025-11424. The attack may be performed from remote. In addition, an exploit is available.