PT-2025-27149 · Unknown · Sfturing Hosp Order

Bi8Bu

·

Published

2025-06-27

·

Updated

2025-06-27

·

CVE-2025-6767

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: sfturing hosp order versions up to 627f426331da8086ce8fff2017d65b1ddef384f8
Description: A critical issue affects the findDoctorByCondition function of the DoctorServiceImpl.java file. The manipulation of the hospitalName argument leads to SQL injection. The attack may be initiated remotely.
Recommendations: For versions up to 627f426331da8086ce8fff2017d65b1ddef384f8, as a temporary workaround, consider disabling the findDoctorByCondition function until a fix is available. Restrict access to the hospitalName argument in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-6767

Affected Products

Sfturing Hosp Order