Record summary

CVE-2019-13396 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 11, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBFlightPath < 4.8.2 / < 5.0-rc2 - Local File InclusionExploitDB exploitby Mohammed AlthibyaniNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMFlightPath - Local File InclusionCVSS 5.3

FlightPath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion.

Impact

This vulnerability can lead to unauthorized access, data leakage, and remote code execution.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-22
Authors0x_Akoko, daffainfo
Template tagscvecve2019flightpathlfiedbgetflightpathvulnvkev
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:getflightpath:flightpath:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3