HitCode hitAppoint 4.5.17 and potentially earlier versions are vulnerable to a critical SQL injection attack. This flaw allows remote attackers to inject malicious SQL commands through the username parameter, potentially leading to complete database compromise, including data theft, modification, and server control.