CVE-2019-13396
Published Jul 10, 2019
Last updated 5 years ago
Overview
- Description
- FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:getflightpath:flightpath:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90B98C24-3E19-4023-A803-4347361F0F39", "versionEndIncluding": "4.8.3", "versionStartIncluding": "4.0" }, { "criteria": "cpe:2.3:a:getflightpath:flightpath:5.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E81EB6CA-1E56-45AE-A305-6B2B78C54C83" }, { "criteria": "cpe:2.3:a:getflightpath:flightpath:5.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D09B0C7B-8950-4A63-9482-7B2C4373DDB6" }, { "criteria": "cpe:2.3:a:getflightpath:flightpath:5.0:dev1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "669DDBAA-8CE1-4CC4-AC07-4F0BB9A6E3F1" }, { "criteria": "cpe:2.3:a:getflightpath:flightpath:5.0:dev2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B12FA442-E52F-4AD7-A0A6-95C0924B1DC4" }, { "criteria": "cpe:2.3:a:getflightpath:flightpath:5.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4E2D730-C825-4C42-A127-906A88A0EE2D" }, { "criteria": "cpe:2.3:a:getflightpath:flightpath:5.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B1CDEFA-B8B8-4B0B-BA13-61302153AD06" }, { "criteria": "cpe:2.3:a:getflightpath:flightpath:5.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF7066E1-DAC9-42CF-BB2C-6EF5187C82AA" } ], "operator": "OR" } ] } ]