Sceawere

Vulnerability Detail

CVE-2026-103540UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Form Tools Server-Side Template Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
formtools.org
Product
Form Tools
Attack Type
Improper Neutralization of Special Elements Used in a Template Engine
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-01T06:17:04.393Z",
  "pubdate": "2026-10-01T06:17:04.393Z",
  "executiveSummary": "A Server-Side Template Injection (SSTI) vulnerability has been identified in Form Tools up to version 3.1.1, specifically within the Client Settings component. This vulnerability arises due to the improper neutralization of special characters within the 'page_titles' argument processed by the 'Clients::updateClientSettingsTab' function in 'global/code/Clients.class.php'.\nThe vulnerability allows a remote attacker to inject arbitrary template syntax, which is subsequently executed by the server-side template engine. Successful exploitation can lead to unauthorized information disclosure, server-side code execution, or full compromise of the application environment. Given that the exploit has been disclosed publicly, the risk is elevated for installations that remain unpatched. As the vendor has not provided an official resolution, organizations must implement manual compensating controls to mitigate the risk of remote code execution.",
  "technicalDetails": "The vulnerability resides in the 'Clients::updateClientSettingsTab' function located in 'global/code/Clients.class.php'. This function is responsible for updating configuration settings for client accounts. The 'page_titles' argument, which is submitted via a POST request during the client settings update process, is passed directly to the server's template engine without adequate sanitization or input validation.\nThe root cause is the failure to neutralize special elements and control characters associated with the underlying template engine. Because the application processes user-supplied input as template directives, an attacker can supply malicious payloads crafted to interact with the server's backend logic. By injecting specific template syntax into the 'page_titles' parameter, an attacker can force the engine to evaluate malicious expressions.\nThe attack flow typically involves an authenticated user with sufficient privileges to modify client settings. The attacker intercepts the request to the client settings update endpoint and replaces the expected legitimate string in the 'page_titles' parameter with a template engine payload. When the server processes this request, the template engine executes the embedded logic instead of rendering it as a static string. This grants the attacker the ability to manipulate application state, access sensitive internal variables, or potentially execute arbitrary system commands if the template engine configuration allows access to system-level functions or classes.\nAffected versions include all releases of Form Tools up to and including 3.1.1. The vulnerability is remotely exploitable, assuming the attacker has access to the administrative interface or the relevant module endpoint. Post-exploitation impact is severe, as SSTI vulnerabilities frequently provide a pathway to remote code execution (RCE) on the underlying host, allowing for complete system takeover, lateral movement within the network, or persistent access. Since the disclosure of the exploit code, the barrier to entry for potential attackers is low, necessitating immediate defensive action in the absence of a vendor-supplied patch."
}
CVE-2026-103540: Form Tools Server-Side Template Injection (MEDIUM Severity, CVSS: 6.3) | Sceawere