{"cve":"CVE-2026-96552","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"code_commit","value":"627f426331da8086ce8fff2017d65b1ddef384f8"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"hosp_order","source":"cna","vendor":"sfturing"},"product":"hosp_order","vendor":"sfturing"}],"created":"2026-09-23T21:45:02.503120+00:00","updated":"2026-09-23T22:00:14.680453+00:00","vendors":["sfturing","sfturing$PRODUCT$hosp_order"]},"mitre":{"cpes":["cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*"],"created":"2026-09-23T20:00:13.847000+00:00","description":"A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.","metrics":{"cvssV2_0":{"score":2.1,"vector":"AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":3.1,"vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"},"cvssV3_1":{"score":3.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"},"cvssV4_0":{"score":2.3,"vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}},"mitre_repo_path":"cves/2026/96xxx/CVE-2026-96552.json","references":["https://github.com/sfturing/hosp_order/","https://github.com/sfturing/hosp_order/issues/123","https://vuldb.com/cve/CVE-2026-96552","https://vuldb.com/submit/907955","https://vuldb.com/vuln/408954","https://vuldb.com/vuln/408954/cti"],"title":"sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt","updated":"2026-09-23T20:00:13.847000+00:00","vendors":["sfturing","sfturing$PRODUCT$hosp_order"],"weaknesses":["CWE-325","CWE-759"]},"nvd":{"cpes":[],"created":"2026-09-23T20:17:26.737000+00:00","description":"A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.","metrics":{"cvssV2_0":{"score":2.1,"vector":"AV:N/AC:H/Au:S/C:P/I:N/A:N"},"cvssV3_0":{},"cvssV3_1":{"score":3.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"},"cvssV4_0":{"score":1.3,"vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-96552.json","references":["https://github.com/sfturing/hosp_order/","https://github.com/sfturing/hosp_order/issues/123","https://vuldb.com/cve/CVE-2026-96552","https://vuldb.com/submit/907955","https://vuldb.com/vuln/408954","https://vuldb.com/vuln/408954/cti"],"title":null,"updated":"2026-09-23T20:17:26.737000+00:00","vendors":[],"weaknesses":["CWE-325","CWE-759"]},"opencve":{"changes":[{"created":"2026-09-23T20:15:00+00:00","data":[{"details":{"new":"A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.","old":null},"type":"description"},{"details":{"new":"sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt","old":null},"type":"title"},{"details":["sfturing","sfturing$PRODUCT$hosp_order"],"type":"first_time"},{"details":{"added":["CWE-325","CWE-759"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["sfturing","sfturing$PRODUCT$hosp_order"],"removed":[]},"type":"vendors"},{"details":{"added":["https://github.com/sfturing/hosp_order/","https://github.com/sfturing/hosp_order/issues/123","https://vuldb.com/cve/CVE-2026-96552","https://vuldb.com/submit/907955","https://vuldb.com/vuln/408954","https://vuldb.com/vuln/408954/cti"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV2_0":{"score":2.1,"vector":"AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":3.1,"vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"},"cvssV3_1":{"score":3.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"},"cvssV4_0":{"score":2.3,"vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"d3cd0164-864c-4ba1-8364-c5e4e6b45e9f"}],"cpes":{"data":["cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-09-23T20:00:13.847000+00:00","provider":"mitre"},"description":{"data":"A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":2.1,"vector":"AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR"},"provider":"mitre"},"cvssV3_0":{"data":{"score":3.1,"vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV3_1":{"data":{"score":3.1,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV4_0":{"data":{"score":2.3,"vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"},"provider":"mitre"},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/sfturing/hosp_order/","https://github.com/sfturing/hosp_order/issues/123","https://vuldb.com/cve/CVE-2026-96552","https://vuldb.com/submit/907955","https://vuldb.com/vuln/408954","https://vuldb.com/vuln/408954/cti"],"providers":["mitre","nvd"]},"title":{"data":"sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt","provider":"mitre"},"updated":{"data":"2026-09-23T20:00:13.847000+00:00","provider":"mitre"},"vendors":{"data":["sfturing","sfturing$PRODUCT$hosp_order"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-325","CWE-759"],"providers":["mitre","nvd"]}}}