在 formtools.org 的 Form Tools(版本 ≤ 3.1.1)中发现了一个漏洞。该漏洞位于 AJAX Endpoint 组件的文件 中的 函数。通过操纵 参数,可触发服务器端请求伪造(SSRF)攻击。该攻击可远程发起。相关利用方法已公开,可能被用于实际攻击。项目方已通过问题报告提前获知此漏洞,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| formtools.org | Form Tools | 3.1.0 |
cpe:2.3:a:form_tools:form_tools:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103540 | 6.3 MEDIUM | formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special |
| CVE-2026-103541 | 6.3 MEDIUM | formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload |
No comments yet