A SQL injection vulnerability has been identified in itsourcecode School Management System version 1.0. The vulnerability exists in the User_Login.php file, where manipulation of the 'email' argument allows an attacker to perform SQL injection. The attack can be executed remotely without requiring local access. A public exploit is already available, increasing the risk of active exploitation. The affected function within User_Login.php is not fully identified but the attack vector is well-documented. This vulnerability poses a significant risk to institutions using this school management software. Organizations running this system should apply patches or mitigations immediately to prevent unauthorized database access or data breaches.