Hi,
I'm a parent of a child at Stantonbury school in Milton Keynes, I actually discovered this whilst doing some testing on schools security - my main problems with this are two fold:
1) It appears user input isn't sanitized, so during my testing I had placed ";SHOW TABLES" as a username
2) When I was informed as to how the backend is linkedin up(I'm not going to place it here for obvious reasons) then there still appears to be a possibility of LDAP injection
Having not seen the source code I can't really comment, but this should be, I think a top priority.