CVE-2026-96549 Details
Description
A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_pro/src/main/java/cn/sfturing/service/impl/CommonUserServiceImpl.java. Such manipulation leads to cleartext storage of sensitive information. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in Sfturing Hosp Order in the file CommonUserServiceImpl.java, specifically in commit 627f426331da8086ce8fff2017d65b1ddef384f8. This issue allows for the cleartext storage of sensitive information, such as registration passwords and password-reset verification codes. The vulnerability can only be exploited in a local environment. The application logs these sensitive details, which can be accessed by anyone with log access or through log aggregation tools.
It is recommended to remove all logging of sensitive information, such as passwords and verification codes. Sensitive data should be redacted before logging, and access to logs should be restricted. Additionally, any exposed credentials or reset codes should be rotated.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sfturing/hosp_order/ | [email protected] | ProductVendor |
| https://github.com/sfturing/hosp_order/issues/120 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-96549 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/907905 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408951 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408951/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-310 | Cryptographic Issues | [email protected] |
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sfturing hosp_order | 627f426331da8086ce8fff2017d65b1ddef384f8 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion