Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.