getflightpath.comConfirmation
http://getflightpath.com/node/2650 CVE-2019-13396
MEDIUMNuclei
getflightpath flightpath Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2019-13396 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
flightpathBrowse getflightpath / flightpath | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBFlightPath < 4.8.2 / < 5.0-rc2 - Local File InclusionExploitDB exploitby Mohammed AlthibyaniNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMFlightPath - Local File InclusionCVSS 5.3
FlightPath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion.
Impact
This vulnerability can lead to unauthorized access, data leakage, and remote code execution.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
WeaknessesCWE-22
Authors0x_Akoko, daffainfo
Template tagscvecve2019flightpathlfiedbgetflightpathvulnvkev
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:getflightpath:flightpath:*:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/47121 http://getflightpath.com/node/2650 https://nvd.nist.gov/vuln/detail/CVE-2019-13396 https://github.com/ARPSyndicate/kenzer-templates https://github.com/d4n-sec/d4n-sec.github.io
Source: ProjectDiscovery
References
3packetstormsecurity.com
http://packetstormsecurity.com/files/153626/FlightPath-Local-File-Inclusion.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-13396