Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.