Description
Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Directory traversal allows a remote attacker to read arbitrary files, obtain sensitive information, and execute arbitrary code on the server. The vulnerability enables disclosure of confidential data and full control over the application, potentially compromising integrity and availability.

Affected Systems

Pronis Loisirs Billetterie CSE, including all versions released prior to April 2026.

Risk and Exploitability

The flaw can be exploited remotely without requiring privileged authentication. No EPSS score is reported and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. Nevertheless, the combination of remote access, file read, and code execution poses a serious risk to affected environments.

Generated by OpenCVE AI on August 17, 2026 at 19:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor patch or update that addresses the directory traversal flaw in Pronis Loisirs Billetterie CSE
  • Restrict the application’s file system access to only the directories required for normal operation
  • Validate and sanitize all user‑supplied path inputs to reject traversal patterns before file operations
  • Enforce minimum user privileges on the files and directories accessed by the application to prevent execution of arbitrary code

Generated by OpenCVE AI on August 17, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Directory Traversal Enabling Remote Code Execution in Pronis Loisirs Billetterie CSE
Weaknesses CWE-22

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T18:13:56.386Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50776

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T19:16:31.980

Modified: 2026-08-17T19:16:31.980

Link: CVE-2026-50776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T20:00:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')