CVE-2026-96551: sfturing hosp_order CommonUserController.java cross-site request forgery
A vulnerability was determined in sfturing hosporder up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssmpro/src/main/java/cn/sfturing/web/CommonUserController.java. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of sfturing hosp_order that include the affected CommonUserController.java code may be exposed. Because the project does not use versioning, affected and unaffected releases cannot be identified from the available information.
What does an attacker need to exploit it?
The attack can be launched remotely and requires user interaction, consistent with a cross-site request forgery attack. No attacker privileges are required.
Is a fix available from the project?
No project response is reported. The issue was reported to the project early, but it had not responded at the time of publication.
What should teams do if they cannot confirm whether their deployment is affected?
Review the deployed source for ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java and assess whether its state-changing actions have CSRF protections. Public exploit disclosure means the issue may be actively usable.