Metrics
Affected Vendors & Products
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sfturing
Sfturing hosp Order |
|
| Vendors & Products |
Sfturing
Sfturing hosp Order |
Mon, 05 Jan 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected by this vulnerability is the function findOrderHosNum of the file /ssm_pro/orderHos/. Such manipulation of the argument hospitalAddress/hospitalName leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | sfturing hosp_order orderHos findOrderHosNum sql injection | |
| Weaknesses | CWE-74 CWE-89 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-05T20:44:41.350Z
Reserved: 2026-01-04T08:42:29.942Z
Link: CVE-2025-15450
Updated: 2026-01-05T20:44:35.661Z
Status : Received
Published: 2026-01-05T02:15:40.930
Modified: 2026-01-05T02:15:40.930
Link: CVE-2025-15450
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:13:23Z