在 sfturing hosp_order 组件中,版本 up to 627f426331da8086ce8fff2017d65b1ddef384f8 中发现了一个安全弱点。受影响的是组件 Order Controller 中文件 中一个未知函数。通过操纵参数 可实现授权绕过(authorization bypass)。该攻击可远程执行。漏洞利用方式已公开,可被用于发起攻击。该产品采用滚动发布(rolling release)模式以实现持续交付,因此无法提供受影响或已修复版本的具体版本信息。项目方已通过问题报告提前
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sfturing | hosp_order | 627f426331da8086ce8fff2017d65b1ddef384f8 |
cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86262 | 7.3 HIGH | sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization |
| CVE-2026-86260 | 6.5 MEDIUM | sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified |
No comments yet