CVE-2026-103542

Source
https://cve.org/CVERecord?id=CVE-2026-103542
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103542.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103542
Published
2026-10-01T05:45:09Z
Modified
2026-10-03T03:30:59Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side request forgery
Details

A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-918"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103542.json"
}
References

Affected packages

Git / github.com/formtools/core

Affected ranges

Type
GIT
Repo
https://github.com/formtools/core
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "3.1.0"
        },
        {
            "last_affected":  "3.1.0"
        },
        {
            "introduced":  "3.1.1"
        },
        {
            "last_affected":  "3.1.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

3.*
3.1.0
3.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103542.json"