CVE-2025-15450

MEDIUM

sfturing hosp_order - SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected by this vulnerability is the function findOrderHosNum of the file /ssm_pro/orderHos/. Such manipulation of the argument hospitalAddress/hospitalName leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.339483
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.339483
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.722925
Various Sources product
https://github.com/sfturing/hosp_order/

Scores

CVSS v3 6.3
EPSS 0.0002
EPSS Percentile 5.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
sfturing/hosp_order 627f426331da8086ce8fff2017d65b1ddef384f8
Published Jan 05, 2026
Tracked Since Feb 18, 2026