What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal.This issue affects PitchPrint: from n/a through <= 11.1.2.
Explanation of Vulnerability in Simple Terms
02Summary
PitchPrint versions up to 11.1.2 contain a path traversal vulnerability that allows an attacker to cause a denial of service by sending specially crafted requests. The vulnerability requires no authentication or user interaction. An attacker can repeatedly trigger the flaw to make the application unavailable.
What an attacker can do
03Attacker Capabilities
Make the PitchPrint application unavailable by triggering a denial of service condition.
Potential impact on your site
04Site Impact
Your PitchPrint service may become unresponsive or crash if an attacker exploits this vulnerability.
Conditions required to exploit
05Prerequisites
Network access to the PitchPrint application; no authentication required.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 28, 2026
Record updated