CVE-2026-38581

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements.
Configurations

No configuration.

History

11 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/theemperorspath/advisories/blob/main/2026/CVE-2026-38581.md - () https://github.com/theemperorspath/advisories/blob/main/2026/CVE-2026-38581.md -
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

11 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 14:16

Updated : 2026-06-11 16:16


NVD link : CVE-2026-38581

Mitre link : CVE-2026-38581

CVE.ORG link : CVE-2026-38581


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')