在 sfturing 的 (版本标识为 627f426331da8086ce8fff2017d65b1ddef384f8 及之前)中发现了安全漏洞。受影响的组件是“密码找回”功能中的 函数,该函数位于 文件中。经过操作可触发未经验证的密码修改漏洞。该漏洞可被远程利用,且已公开披露的利用代码已被用于实际攻击。由于该产品采用持续交付的滚动发布模式,因此未提供受影响或已修复版本的具体信息。项目方此前已通过问题报告得知该问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sfturing | hosp_order | 627f426331da8086ce8fff2017d65b1ddef384f8 |
cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86261 | 7.3 HIGH | sfturing hosp_order Order Controller OrderController.java authorization |
| CVE-2026-86262 | 7.3 HIGH | sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization |
No comments yet