Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.
https://github.com/kishan0725/Hospital-Management-System
https://gist.github.com/celbahraoui/f5343ffba6e99bd0a65bd36d21a679c6