A SQL injection vulnerability has been identified in code-projects Online Shopping System version 1.0. The vulnerability exists in the /action.php file within the Search Functionality component, where the 'keyword' argument is not properly sanitized. An attacker can manipulate this parameter to perform time-based blind SQL injection attacks. The attack can be initiated remotely without requiring physical access to the target system. A public exploit has already been disclosed and is available for use, increasing the risk of active exploitation. The affected software is a web-based online shopping platform. This vulnerability poses a significant risk to data confidentiality and integrity as unauthorized database access may be achieved. Organizations using this software should apply patches or mitigations immediately.