Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.
https://hakaisecurity.io/error-404-your-security-not-found-tales-of-web-vulnerabilities/