CPE
The onetwothreeneth HospitalManagementSystem contains a remote SQL injection vulnerability in edit_accounts.php that allows unauthenticated attackers to execute arbitrary database queries.