CVE-2026-103542
- EPSS 0.22%
- Veröffentlicht 01.10.2026 05:45:09
- Zuletzt bearbeitet 06.10.2026 01:16:33
A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The atta...
CVE-2026-103541
- EPSS 0.21%
- Veröffentlicht 01.10.2026 05:30:10
- Zuletzt bearbeitet 01.10.2026 15:17:28
A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible...
CVE-2026-103540
- EPSS 0.24%
- Veröffentlicht 01.10.2026 05:15:13
- Zuletzt bearbeitet 01.10.2026 20:17:23
A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation ...
CVE-2024-6936
- EPSS 0.4%
- Veröffentlicht 21.07.2024 04:15:02
- Zuletzt bearbeitet 21.11.2024 09:50:35
A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/settings/index.php?page=accounts of the component Setting Handler. The manipulation ...
CVE-2024-6937
- EPSS 0.37%
- Veröffentlicht 21.07.2024 04:15:02
- Zuletzt bearbeitet 21.11.2024 09:50:35
A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.php of the component Import Option List. The manipulation of the argument...
CVE-2024-6935
- EPSS 0.32%
- Veröffentlicht 21.07.2024 03:15:02
- Zuletzt bearbeitet 21.11.2024 09:50:35
A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknown code of the file /admin/clients/ of the component User Settings Page. The manipulation leads to cross site scripting. The attack...
CVE-2024-6934
- EPSS 0.39%
- Veröffentlicht 21.07.2024 02:15:02
- Zuletzt bearbeitet 21.11.2024 09:50:34
A vulnerability classified as problematic has been found in formtools.org Form Tools 3.1.1. This affects an unknown part of the file /admin/forms/add/step2.php?submission_type=direct. The manipulation of the argument Form URL leads to cross site scri...
CVE-2024-22717
- EPSS 0.37%
- Veröffentlicht 11.04.2024 20:15:33
- Zuletzt bearbeitet 08.04.2025 15:20:24
Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.
CVE-2024-22718
- EPSS 0.66%
- Veröffentlicht 11.04.2024 20:15:33
- Zuletzt bearbeitet 08.04.2025 15:20:32
Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.
CVE-2024-22719
- EPSS 0.54%
- Veröffentlicht 11.04.2024 20:15:33
- Zuletzt bearbeitet 08.04.2025 15:20:41
SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.