Junglewise Threat Intelligence

CVE-2026-38579: damasac thaipalliative_lte reflected XSS in ezform.php

CVE-2026-38579 · Severity: info · CVSS 6.1 · Published 2026-06-05

Executive brief

thaipalliative_lte is a web-based application used for palliative care data management. Multiple security flaws allow attackers to inject malicious scripts into the application's pages. If a user clicks a specially crafted link, an attacker could steal login session information, perform actions on behalf of the user, or display fraudulent content.

Technical details

Multiple reflected Cross-Site Scripting (XSS) vulnerabilities exist in the /substudy/ezform.php component of thaipalliative_lte. The application fails to sanitize or encode user-supplied input from the 'idFormMain', 'id', and 'ptid_key' parameters before echoing them into HTML attributes and JavaScript contexts. A remote, unauthenticated attacker can exploit these flaws by tricking a victim into clicking a malicious URL, leading to arbitrary JavaScript execution in the context of the victim's browser session. As of the disclosure date, no official patch has been released.

Affected products

  • damasac thaipalliative_lte 1.0 through 3.0

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats