๐Ÿ” CVE Alert

CVE-2026-96552

LOW 3.1

sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-759 CWE-325
Vendor sfturing
Product hosp_order
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for sfturing hosp_order

Be the first to know when new low vulnerabilities affecting sfturing hosp_order are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

sfturing / hosp_order
627f426331da8086ce8fff2017d65b1ddef384f8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/408954 vuldb.com: https://vuldb.com/vuln/408954/cti vuldb.com: https://vuldb.com/cve/CVE-2026-96552 vuldb.com: https://vuldb.com/submit/907955 github.com: https://github.com/sfturing/hosp_order/issues/123 github.com: https://github.com/sfturing/hosp_order/

Credits

๐Ÿ” gscsd (VulDB User) VulDB CNA Team