A vulnerability categorized as critical has been discovered in code-projects COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injection.
This vulnerability was named CVE-2025-13585. The attack may be performed from remote. In addition, an exploit is available.