A SQL injection vulnerability has been identified in itsourcecode Payroll System version 1.0. The vulnerability resides in the Login function within the admin_class.php file. Attackers can manipulate the Username argument to perform SQL injection attacks. The vulnerability is remotely exploitable, requiring no physical access to the target system. A public exploit has already been disclosed, increasing the risk of active exploitation. The affected product is a payroll management system, making it a sensitive target due to the financial and personal data it handles. No authentication is required to trigger the vulnerability, as it exists in the login mechanism itself. Organizations using this software are advised to apply patches or mitigations immediately.