Critical severity9.8NVD Advisory· Published Jun 11, 2026· Updated Jun 11, 2026
CVE-2026-38581
CVE-2026-38581
Description
SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=3.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.