Impact
Directory traversal allows a remote attacker to read arbitrary files, obtain sensitive information, and execute arbitrary code on the server. The vulnerability enables disclosure of confidential data and full control over the application, potentially compromising integrity and availability.
Affected Systems
Pronis Loisirs Billetterie CSE, including all versions released prior to April 2026.
Risk and Exploitability
The flaw can be exploited remotely without requiring privileged authentication. No EPSS score is reported and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. Nevertheless, the combination of remote access, file read, and code execution poses a serious risk to affected environments.
OpenCVE Enrichment