EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all intelligence correlata
Vulnerabilità

CVE-2026-95396

Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.

Condivisione
PUBLIC-OSINT
Confidenza
100
Fonte
The CVE Program
Aggiornata
26/09/2026 03:28

Descrizione

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the component Public Search Handlers. The manipulation of the argument Search leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Identificativo STIXvulnerability--2d505c51-f52d-5655-a80c-48e92b70d4e6
Prima osservazione-
Ultima osservazione-
Relazioni censite12

Alias e classificazioni

CWE-79CWE-94Code InjectionCross Site Scripting

Dettagli tecnici minimizzati

Nessun dato grezzo
cisa kev
False
cvss vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
cvss severity
MEDIUM
cvss score
4.3
Provenienza

Riferimenti pubblici

Correlazione EudorIA

Catalogo Intel

La vulnerabilità è presente anche nel catalogo editoriale EudorIA.

Apri analisi EudorIA

La presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.