BMIT BMS version 2.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.