← Back

Getflightpath

getflightpath

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Flightpath
flightpath

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Getflightpath
1Flightpath
Jun 17, 2026
Nov 15, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malici...Show more
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.Show less
1Getflightpath
1Flightpath
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
1Getflightpath
1Flightpath
Jun 17, 2026
Jul 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_su...Show more
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.Show less