A vulnerability labeled as critical has been found in Harsh21Patel Inventory-Management-System-PHP. The affected element is the function mysqli_query of the file login.php of the component Authentication. The manipulation of the argument email/password/id results in sql injection.

This vulnerability is reported as CVE-2026-71248. The attack can be launched remotely. No exploit exists.