A SQL injection vulnerability has been identified in code-projects Simple Inventory System version 1.0. The vulnerability resides in the file /InventoryManagement/edit.php, where manipulation of the 'ID' argument allows an attacker to perform SQL injection attacks. The attack can be carried out remotely without requiring physical access to the target system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability is tracked as CVE-2026-79845 and has been assigned a high criticality rating. Affected users of Simple Inventory System 1.0 should apply patches or mitigations as soon as possible. The availability of a public exploit significantly raises the likelihood of widespread exploitation in the wild.