PT-2026-46963 · Damasac · Thaipalliative Lte
CVE-2026-38579
·
Published
2026-06-05
·
Updated
2026-06-05
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
damasac thaipalliative lte versions prior to 3.1
Description
Multiple reflected Cross-Site Scripting (XSS) issues exist where user input is echoed into HTML attributes and JavaScript contexts without proper encoding. This allows remote attackers to inject arbitrary web script or HTML through the '/substudy/ezform.php' endpoint using the
idFormMain, id, and ptid key parameters.Recommendations
Update damasac thaipalliative lte to a version later than 3.0.
As a temporary workaround, restrict access to the '/substudy/ezform.php' endpoint or sanitize the
idFormMain, id, and ptid key parameters to prevent script injection.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thaipalliative Lte