Junglewise Threat Intelligence

CVE-2026-38581: damasac thaipalliative_lte SQL injection in ezform.php

CVE-2026-38581 · Severity: info · CVSS 9.8 · Published 2026-06-11

Executive brief

A security vulnerability exists in the thaipalliative_lte software, which is used for palliative care data management. An attacker can send specially crafted web requests to take control of the underlying database, allowing them to view, modify, or delete sensitive patient and administrative records. This issue occurs because the software does not properly verify information provided by users before using it in database commands.

Technical details

A SQL injection vulnerability exists in damasac thaipalliative_lte versions 1.0 through 3.0 due to improper input sanitization in /substudy/ezform.php. The application concatenates the 'idFormMain' (GET) and 'id' (REQUEST) parameters directly into SQL query strings without using prepared statements or escaping functions like mysqli_real_escape_string(). An unauthenticated remote attacker can exploit this by supplying malicious SQL commands to the affected parameters, leading to unauthorized data extraction, modification, or full database compromise. As of the advisory date, no patch is available.

Affected products

  • damasac thaipalliative_lte 1.0 through 3.0

Timeline

  • 2026-06-05: disclosed: Vulnerability discovered by Jackson Mittag (0dayscyber)
  • 2026-06-11: advisory: CVE-2026-38581 published

References

Related threats