CVE-2026-103542 | formtools.org Form Tools up to 3.1.1 AJAX Endpoint /global/code/actions.php smart_fill url server-side request forgery (Issue 958)
A vulnerability identified as problematic has been detected in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery.
This vulnerability is handled as CVE-2026-103542. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More