Executive brief
Sfturing ssm_pro is a hospital appointment management system. An unauthenticated attacker can inject malicious JavaScript code into appointment fields (hospital name, department, or doctor name) when creating orders. When other users view their appointment records, the stored malicious script executes in their browsers, potentially allowing the attacker to steal session data or perform unauthorized actions on behalf of victims.
Technical details
This is a stored cross-site scripting (CWE-79) vulnerability in the order creation endpoint (/order) of the OrderController. The vulnerable component accepts user-supplied input for hospitalName, officesName, and doctorName without validation or sanitization, stores it directly in the database, and later renders it in JSP templates using raw EL expressions (${orderRecords.hospitalName}) without HTML encoding. The vulnerability requires user interaction (a victim must view the contaminated appointment record) but no authentication is required to create a malicious appointment. An attacker can execute arbitrary JavaScript in the context of the affected user's session. The project was notified on 2026-07-22 but has not yet provided a patch.
Affected products
- Sfturing ssm_pro up to commit 627f426331da8086ce8fff2017d65b1ddef384f8
Timeline
- 2026-07-22: disclosed: Vulnerability disclosed via GitHub issue #117
- 2026-09-07: advisory: CVE-2026-86264 published