Showing 1 vulnerability on this page for flightpath

Signals CISA KEV Ransomware Nuclei
getflightpath vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

getflightpath flightpath Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

CWE-22Jul 10, 20191 related artifact
CVSS5.3v3.0EPSS62.6%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX