Filtered by vendor Getflightpath Subscriptions
Filtered by product Flightpath Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-15227 1 Getflightpath 1 Flightpath 2019-08-28 N/A
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
CVE-2019-13396 1 Getflightpath 1 Flightpath 2019-07-17 N/A
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.