在 sfturing hosp_order(版本上限至 627f426331da8086ce8fff2017d65b1ddef384f8)中发现了一个安全漏洞。该问题影响文件 ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java 中的 getProperties 函数。利用该漏洞可实现敏感信息的明文传输。攻击者可远程发起攻击。攻击复杂度较高,可利用性评估为困难。该漏洞的利用代码已被公开,且可能被实际利用。 该产品采用持续交付与滚动发布模式,因此无法提供受影响版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sfturing | hosp_order | 627f426331da8086ce8fff2017d65b1ddef384f8 |
cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96548 | 5.6 MEDIUM | sfturing hosp_order jdbc.properties hard-coded credentials |
| CVE-2026-96551 | 4.3 MEDIUM | sfturing hosp_order CommonUserController.java cross-site request forgery |
| CVE-2026-96549 | 3.3 LOW | sfturing hosp_order CommonUserServiceImpl.java cleartext storage |
| CVE-2026-96552 | 3.1 LOW | sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt |
No comments yet