CVE-2025-6767 is a critical SQL injection vulnerability affecting the sfturing hosp_order application, specifically within the findDoctorByCondition function of the DoctorServiceImpl.java file. This flaw allows remote attackers to manipulate the hospitalName argument, leading to unauthorized database access. While rated as Medium severity by CVSS (6.3), its critical classification and public disclosure of exploit details warrant immediate attention. There is no evidence of active exploitation, nor are there Metasploit, Nuclei, or ExploitDB modules available, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sfturing | Hosp Order | 627f426331da8086ce8fff2017d65b1ddef384f8CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.