在 formtools.org 的 Form Tools(版本 ≤ 3.1.1)中检测到一项安全漏洞。该漏洞影响“客户端设置”组件中 文件里的 函数。对参数 的操纵会导致模板引擎中使用的特殊元素未被正确中和(即存在模板注入风险)。攻击者可远程发起此攻击。该漏洞的利用方法已公开披露,可能被恶意利用。项目方已通过问题报告提前获知该问题,但至今未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| formtools.org | Form Tools | 3.1.0 |
cpe:2.3:a:form_tools:form_tools:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103541 | 6.3 MEDIUM | formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload |
| CVE-2026-103542 | 4.3 MEDIUM | formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery |
No comments yet