PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy. | |
| Title | PictShare < 3.7.1 Sensitive Information Disclosure via info API | |
| First Time appeared |
Hascheksolutions
Hascheksolutions pictshare |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hascheksolutions
Hascheksolutions pictshare |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T21:08:37.900Z
Reserved: 2026-10-01T17:52:44.371Z
Link: CVE-2026-104051
No data.
Status : Received
Published: 2026-10-01T22:17:00.833
Modified: 2026-10-01T22:17:00.833
Link: CVE-2026-104051
No data.
OpenCVE Enrichment
No data.
Weaknesses