Vendor
The UNION HospitalManagementSystem is vulnerable to remote SQL injection via the patient_id parameter in patient_info.php, allowing unauthenticated attackers to manipulate database queries.