phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.
mitre·CWE-89·Published 2025-08-25