E SMS Scripg contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the /admin/adminlogin.php script not properly sanitizing user-supplied input to the 'Password' field. This may allow an attacker to manipulate an SQL query that will result in bypassing authentication. Once authenticated, the attacker will have access to the application with the same privileges as the administrator account used during the authentication bypass.