Impact
A flaw in suite utilities for sfturing hosp_order allows the getProperties method to send sensitive information over the network in clear text. The vulnerability is triggered by manipulating the MailUtil configuration and can be initiated from a remote location, exposing credentials and other confidential data. It is classified under CWE-310 and CWE-319, indicating improper handling of encryption and insecure communication channels.
Affected Systems
The affected product is sfturing hosp_order. No specific release numbers are listed, but the issue exists in all versions up to commit 627f426331da8086ce8fff2017d65b1ddef384f8. The project uses continuous delivery with rolling releases, so affected implementations may vary until an official fix is released.
Risk and Exploitability
The vulnerability has a CVSS score of 6.3, depicting a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely, but the complexity is described as high, making successful exploitation difficult. Because the exploit logic has been made public, it could be adopted by threat actors, yet the overall risk remains moderate due to the lack of a known widespread attack vector and the vendor’s pending response.
OpenCVE Enrichment