Product
Hospital Information System 1.0 is vulnerable to unauthenticated remote SQL injection via the 'email' parameter in the User::login function, allowing for unauthorized database access.