Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.Referenceshttps://github.com/Luc1f3r066/Client-Management-System-v1.0-