在 formtools.org 的 Form Tools(版本 ≤ 3.1.1)中检测到一个漏洞。该问题影响 Ajax Handler 组件中 文件里的 函数。攻击者可通过操纵该函数实现不受限制的文件上传,并支持远程发起攻击。目前该漏洞的利用方法已公开,可能被恶意使用。项目方此前已通过问题报告获知此问题,但至今未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| formtools.org | Form Tools | 3.1.0 |
cpe:2.3:a:form_tools:form_tools:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103540 | 6.3 MEDIUM | formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special |
| CVE-2026-103542 | 4.3 MEDIUM | formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery |
No comments yet