Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.