Sceawere

Vulnerability Detail

CVE-2026-103541UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Form Tools Unrestricted File Upload

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
formtools.org
Product
Form Tools
Attack Type
Unrestricted Upload
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-01T06:17:05.630Z",
  "pubdate": "2026-10-01T06:17:05.630Z",
  "executiveSummary": "A critical unrestricted file upload vulnerability exists in Form Tools version 3.1.1 and earlier, specifically within the Ajax Handler component.\nThe vulnerability resides in the Files::uploadFile function within global/code/actions.php, allowing remote attackers to upload arbitrary files to the server.\nBy bypassing file validation mechanisms, an unauthenticated or remote attacker can upload malicious scripts, such as web shells, leading to potential Remote Code Execution (RCE).\nThis flaw presents a significant security risk, as the exploit is publicly available and the vendor has not yet addressed the report.\nSuccessful exploitation grants an attacker the ability to execute arbitrary code on the underlying web server, potentially leading to a full system compromise, data exfiltration, or unauthorized modification of the application environment.\nImmediate defensive action is required to restrict access to the affected component until an official security patch is released.",
  "technicalDetails": "The vulnerability is located in the Files::uploadFile function within the file global/code/actions.php, which serves as part of the Form Tools Ajax Handler component.\nThe root cause is an insufficient validation mechanism during the file upload process, which fails to verify or sanitize the file type, extension, or content before saving the uploaded object to the server's filesystem.\nThe attack flow begins with a remote attacker identifying the entry point within the Ajax Handler. Since the application does not implement strict server-side validation or enforcement of allowed MIME types and file extensions, an attacker can craft a multipart/form-data POST request containing a malicious payload.\nBy bypassing the intended file restrictions, an attacker can upload executable files (e.g., .php, .phtml, or other server-side scripting languages) directly into a web-accessible directory.\nOnce the file is uploaded, the attacker can trigger the execution of the payload by requesting the resource directly via a standard HTTP GET request. This facilitates arbitrary code execution with the permissions of the web server process (e.g., www-data).\nThe exploitation does not require advanced user interaction, and given the nature of the Ajax Handler, the process can be fully automated. The ability to upload files remotely allows for rapid deployment of backdoors, web shells, or other malicious artifacts, enabling persistent access for the attacker.\nPost-exploitation impact includes full control over the application's environment, potential access to the underlying database, unauthorized configuration changes, and the ability to pivot to other systems within the internal network. Because the vulnerability is publicly disclosed, the probability of exploitation attempts is high for any instance that remains exposed to the public internet.\nThe vulnerability affects all versions of Form Tools up to and including 3.1.1. Due to the lack of input validation, the system cannot distinguish between legitimate user-uploaded documents and malicious executable scripts, making the current architecture of the Files::uploadFile function fundamentally insecure against this vector."
}
CVE-2026-103541: Form Tools Unrestricted File Upload (MEDIUM Severity, CVSS: 6.3) | Sceawere