Vulnerabilities (CVE)

Filtered by vendor Getflightpath Subscribe
Filtered by product Flightpath
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15227 1 Getflightpath 1 Flightpath 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
CVE-2019-13396 1 Getflightpath 1 Flightpath 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.