Hospital Management System version 1.0 suffers from insecure direct object reference and account takeover vulnerabilities.