← العودة للجدول
CVE-2026-38581
CVE-2026-38581 — SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 al
📅 2026-06-11
🔴 Critical 🔥 No NVD Vulnerability Web CVSS 9.8

📋 الوصف الكامل

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements.

💻 الأنظمة المتأثرة

PHP

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-38581

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←