Product
The bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL is vulnerable to remote SQL injection via the 'Username' argument in /admin_transaction.php, allowing unauthorized database access.