A vulnerability, which was classified as critical, has been found in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument uemail causes sql injection.
This vulnerability is tracked as CVE-2025-11611. The attack is possible to be carried out remotely. Moreover, an exploit is present.