CNNVD-202506-3522 Information

CNNVD ID

CNNVD-202506-3522

CVE-2025-6767

  • CNNVD Published: 2025-06-27

Description (Chinese)

hosporder是中国Xiaohao.Shi个人开发者的一个医院预约挂号系统。 hosporder存在注入漏洞,该漏洞源于文件DoctorServiceImpl.java中参数hospitalName的错误操作导致SQL注入。

Description (English)

Hosporder is a hospital booking system for Xiaohao.Shi personal developers in China. There is an injection loophole in the hosporder that results from an error in the hospitalName parameter in the document Doctor ServiceImpl.java, resulting in the injection of SQL.

Hazard Level

High

Vulnerability Type

注入

Affected Vendor

Live Support

Published

2025-06-27

Last Modified

2026-02-24

References

https://github.com/sfturing/hosp_order/issues/109 https://vuldb.com/?ctiid.314081 https://vuldb.com/?id.314081 https://vuldb.com/?submit.600547

Share on: