Executive brief
thaipalliative_lte is a web-based application used for palliative care data management. Multiple security flaws allow attackers to inject malicious scripts into the application's pages. If a user clicks a specially crafted link, an attacker could steal login session information, perform actions on behalf of the user, or display fraudulent content.
Technical details
Multiple reflected Cross-Site Scripting (XSS) vulnerabilities exist in the /substudy/ezform.php component of thaipalliative_lte. The application fails to sanitize or encode user-supplied input from the 'idFormMain', 'id', and 'ptid_key' parameters before echoing them into HTML attributes and JavaScript contexts. A remote, unauthenticated attacker can exploit these flaws by tricking a victim into clicking a malicious URL, leading to arbitrary JavaScript execution in the context of the victim's browser session. As of the disclosure date, no official patch has been released.
Affected products
- damasac thaipalliative_lte 1.0 through 3.0
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory