在组件“订单取消”中检测到一个漏洞,影响范围为 sfturing 的 hosp_order 仓库(commit 哈希:627f426331da8086ce8fff2017d65b1ddef384f8)。该漏洞位于文件 中的函数 。对参数 的操作会导致授权绕过(Authorization Bypass)。攻击者可以从远程发起该攻击。利用该漏洞的代码已公开,并且可能已被实际利用。该产品的发布模式为滚动发布(rolling release),用于持续交付,因此受影响版本及修复版本的具体版本信息未公开。项目方已通过问题报告
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sfturing | hosp_order | 627f426331da8086ce8fff2017d65b1ddef384f8 |
cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86261 | 7.3 HIGH | sfturing hosp_order Order Controller OrderController.java authorization |
| CVE-2026-86262 | 7.3 HIGH | sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization |
| CVE-2026-86260 | 6.5 MEDIUM | sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified |
| CVE-2026-86264 | 4.3 MEDIUM | sfturing ssm_pro Order Endpoint OrderController.java cross site scripting |
No comments yet