PT-2026-104028 · Hascheksolutions · Pictshare

·

CVE-2026-104356

·

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-104356

Produtos afetados

Pictshare