CVE-2026-96552

Published: Set 23, 2026 Last Modified: Set 24, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 1,3
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW 3,1
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
LOW 2,1
Access Vector: network
Access Complexity: high
Authentication: single
Confidentiality: partial
Integrity: none
Availability: none

Description

AI Translation Available

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

325

Missing Cryptographic Step

Draft
Common Consequences
Security Scopes Affected:
Access Control Confidentiality Integrity Accountability Non-Repudiation
Potential Impacts:
Bypass Protection Mechanism Read Application Data Modify Application Data Hide Activities
Applicable Platforms
All platforms may be affected
View CWE Details
759

Use of a One-Way Hash without a Salt

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/sfturing/hosp_order/
https://github.com/sfturing/hosp_order/issues/123
https://vuldb.com/cve/CVE-2026-96552
https://vuldb.com/submit/907955
https://vuldb.com/vuln/408954
https://vuldb.com/vuln/408954/cti