CVE-2025-15450

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected by this vulnerability is the function findOrderHosNum of the file /ssm_pro/orderHos/. Such manipulation of the argument hospitalAddress/hospitalName leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

05 Jan 2026, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-05 02:15

Updated : 2026-01-08 18:09


NVD link : CVE-2025-15450

Mitre link : CVE-2025-15450

CVE.ORG link : CVE-2025-15450


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')