Unrestricted File Upload Vulnerability in Form Tools by formtools.org
CVE-2026-103541
Key Information:
- Vendor
Formtools.org
- Status
- Vendor
- CVE Published:
- 1 October 2026
Badges
What is CVE-2026-103541?
A vulnerability was discovered in Form Tools that allows for unrestricted file uploads due to a flaw in the uploadFile function within the Ajax Handler component. This issue is present in versions up to 3.1.1. The flaw enables remote attackers to exploit the vulnerability and upload arbitrary files, posing a significant security risk. Despite being informed of this issue, the developers have yet to respond effectively, leaving users vulnerable to potential attacks. The exploit is now publicly accessible, increasing the urgency for users to address this issue promptly.
Affected Version(s)
Form Tools 3.1.0
Form Tools 3.1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
