Server-Side Template Injection Vulnerability in FormTools by formtools.org
CVE-2026-103540
Key Information:
- Vendor
Formtools.org
- Status
- Vendor
- CVE Published:
- 1 October 2026
Badges
What is CVE-2026-103540?
A security vulnerability has been identified in the Form Tools application, specifically impacting versions up to 3.1.1. This flaw affects the function 'Clients::updateClientSettingsTab' within the Client Settings component, located in 'global/code/Clients.class.php'. The issue arises from the improper handling of the 'page_titles' argument, resulting in insufficient protection against the manipulation of special elements typically utilized by a template engine. Given that this vulnerability can be exploited remotely, it poses a significant risk to users. The project was notified of this issue early via an issue report but has yet to issue a response. Appropriate measures should be taken to secure affected instances.
Affected Version(s)
Form Tools 3.1.0
Form Tools 3.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
