CVE-2026-104051
🟡 Monitoruj
W PictShare przed 3.7.1 ujawnienie informacji pozwala na usunięcie plików przez nieautoryzowanych użytkowników.
CVSS
8.2
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.2 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-10-01 22:17:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:47:49 UTC |
Referencje
- https://github.com/HaschekSolutions/pictshare/commit/ce5fc474e89769efeae25fee763894bcce3412e3 ([email protected])
- https://github.com/HaschekSolutions/pictshare/releases/tag/v3.7.1 ([email protected])
- https://www.vulncheck.com/advisories/pictshare-sensitive-information-disclosure-via-info-api ([email protected])