PT-2026-104019 · Pictshare · Pictshare
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PictShare versions prior to 3.7.1
Description
An information disclosure issue exists where unauthenticated attackers can obtain the secret
delete code and uploader metadata. This occurs when calling the 'API::info()' endpoint, which returns the complete raw metadata object without a field whitelist. By using a publicly visible file hash, an attacker can retrieve the delete code and subsequently use the delete API to permanently remove arbitrary files. Additionally, this exposes the uploader IP, User Agent, remote port, and SHA-1 hash, compromising content integrity, availability, and uploader privacy.Recommendations
Update PictShare to version 3.7.1 or later.
Restrict access to the 'API::info()' endpoint to minimize the risk of metadata exposure.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pictshare