Executive brief
Pronis Loisirs Billetterie is a ticketing and employee benefits management platform used by corporate social committees (CSE) in France. A directory traversal vulnerability allows unauthenticated remote attackers to read sensitive server files—including system configuration and SSH credentials—and potentially execute arbitrary code, threatening the confidentiality of employee and organizational data.
Technical details
A directory traversal vulnerability exists in the getfile.php endpoint that fails to properly validate user-supplied file path input. An attacker can exploit this by submitting path traversal sequences (e.g., "../../../") to access files outside the intended directory, such as /etc/passwd and configuration files containing SSH credentials. The vulnerability is network-accessible without authentication and can lead to information disclosure and potentially arbitrary code execution. No patch availability is documented in the advisory.
Affected products
- Pronis Loisirs Billetterie CSE < 04/2026
Timeline
- 2026-08-17: disclosed: CVE-2026-50776 published on NVD