Description
A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java. Performing a manipulation results in cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is assessed as difficult. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-23
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Patch
AI Analysis

Impact

A flaw in suite utilities for sfturing hosp_order allows the getProperties method to send sensitive information over the network in clear text. The vulnerability is triggered by manipulating the MailUtil configuration and can be initiated from a remote location, exposing credentials and other confidential data. It is classified under CWE-310 and CWE-319, indicating improper handling of encryption and insecure communication channels.

Affected Systems

The affected product is sfturing hosp_order. No specific release numbers are listed, but the issue exists in all versions up to commit 627f426331da8086ce8fff2017d65b1ddef384f8. The project uses continuous delivery with rolling releases, so affected implementations may vary until an official fix is released.

Risk and Exploitability

The vulnerability has a CVSS score of 6.3, depicting a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely, but the complexity is described as high, making successful exploitation difficult. Because the exploit logic has been made public, it could be adopted by threat actors, yet the overall risk remains moderate due to the lack of a known widespread attack vector and the vendor’s pending response.

Generated by OpenCVE AI on September 23, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether sfturing has released an updated version or security patch and apply it immediately.
  • If no patch is available, restrict the exposure of the getProperties function by firewall rule or network segmentation, and enforce TLS for all outbound mail connections to prevent cleartext transmission.
  • Monitor outbound traffic for unexpected plaintext credentials and alert on anomalies to detect any exploitation attempts.

Generated by OpenCVE AI on September 23, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java. Performing a manipulation results in cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is assessed as difficult. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title sfturing hosp_order MailUtil.java getProperties cleartext transmission
First Time appeared Sfturing
Sfturing hosp Order
Weaknesses CWE-310
CWE-319
CPEs cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*
Vendors & Products Sfturing
Sfturing hosp Order
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sfturing Hosp Order
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-23T19:30:10.614Z

Reserved: 2026-09-23T12:48:00.185Z

Link: CVE-2026-96550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T20:17:26.350

Modified: 2026-09-23T20:17:26.350

Link: CVE-2026-96550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:45:09Z

Weaknesses