PT-2026-48664 · Undefined · Undefined

Published

2026-06-11

·

Updated

2026-06-11

·

CVE-2026-38581

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SQL Injection vulnerability in damasac thaipalliative lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-38581

Affected Products

Undefined