在 sfturing hosp_order(版本号上限为 627f426331da8086ce8fff2017d65b1ddef384f8)中发现了一个漏洞。受影响的文件是 ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java 中的某个未知函数。利用该漏洞可能引发跨站请求伪造(CSRF)。该攻击可以远程发起。该利用工具已被公开披露,可能被他人利用。本产品未采用版本控制,因此无法提供受影响和不受影响的具体版本信息。项目方已通过问题报告尽早得知此
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sfturing | hosp_order | 627f426331da8086ce8fff2017d65b1ddef384f8 |
cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96548 | 5.6 MEDIUM | sfturing hosp_order jdbc.properties hard-coded credentials |
| CVE-2026-96550 | 3.7 LOW | sfturing hosp_order MailUtil.java getProperties cleartext transmission |
| CVE-2026-96549 | 3.3 LOW | sfturing hosp_order CommonUserServiceImpl.java cleartext storage |
| CVE-2026-96552 | 3.1 LOW | sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt |
No comments yet