A SQL injection vulnerability has been identified in rabindralamsal's inventory-management-system version 1.0.0. The flaw exists in the index.php file within the Login component, where manipulation of the username and/or password arguments can lead to SQL injection. The vulnerability is remotely exploitable, meaning an attacker does not need local access to the system. A public exploit has already been published, increasing the risk of active exploitation. The affected product is a web-based inventory management application. No authentication is required to exploit the vulnerability, as it resides in the login functionality. This represents a significant risk to organizations running this software version.