Home

Description

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements.

PUBLISHED Reserved 2026-04-06 | Published 2026-06-11 | Updated 2026-06-11 | Assigner mitre

References

github.com/...th/advisories/blob/main/2026/CVE-2026-38581.md exploit

github.com/...ba524533062ef5244e9b7c4380/substudy/ezform.php

github.com/...th/advisories/blob/main/2026/CVE-2026-38581.md

cve.org (CVE-2026-38581)

nvd.nist.gov (CVE-2026-38581)

Download JSON