CVE-2026-103541
Received Received - Intake

Unrestricted File Upload in Form Tools

Vulnerability report for CVE-2026-103541, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
formtools form_tools to 3.1.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unrestricted file upload flaw in FormTools version 3.1.1. It allows authenticated users, including low-privileged ones, to upload arbitrary PHP files to the server's web-accessible upload directory without proper validation. The issue occurs in the Files::uploadFile function of global/code/actions.php, where missing checks on file extensions, MIME types, and content enable attackers to upload malicious PHP scripts. These files can then be executed remotely via URL, leading to potential remote code execution.

Detection Guidance

Check for unauthorized PHP files in the upload directory (default: rootDir/upload). Look for files with names like ft_sf_tmp_*.php or unexpected PHP files. Use commands like 'find /path/to/upload -name "*.php" -type f' to search for PHP files in the upload directory. Monitor network traffic for POST requests to /global/code/actions.php with action=upload_scraped_page_for_smart_fill.

  • Inspect server logs for suspicious file uploads or execution attempts in the upload directory.
Impact Analysis

An attacker could exploit this to upload a PHP web shell, gaining full control over the server with the same privileges as the web application. This could lead to data theft, unauthorized access to sensitive information, defacement of websites, or further attacks on connected systems. Even low-privileged users can exploit this if they are authenticated.

Compliance Impact

This vulnerability could lead to severe compliance violations. GDPR requires protecting personal data; a breach could result in fines. HIPAA mandates safeguarding health information; unauthorized access risks penalties. The flaw enables data theft and system compromise, directly violating confidentiality and integrity requirements of these regulations.

Mitigation Strategies

Disable the smart_fill feature in FormTools if not required. Restrict access to the upload directory by disabling script execution (e.g., via .htaccess or server configuration). Implement strict file validation: allow only specific file types, validate MIME types and content, and use random filenames. Add CSRF protection and restrict the upload endpoint to administrators only.

  • Temporarily block write access to the upload directory or move it outside the web root until patches are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103541. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart