A SQL injection vulnerability has been identified in the code-projects Task Management System In PHP version 1.0. The vulnerability exists in the /index.php file within the Login component, where the 'email' parameter is susceptible to SQL injection attacks. An unauthenticated remote attacker can exploit this vulnerability by manipulating the email argument to inject malicious SQL code. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. This type of vulnerability can lead to unauthorized access, data exfiltration, or complete database compromise. The attack requires no special privileges or user interaction, making it particularly dangerous. Organizations using this task management system should apply patches or mitigations immediately.