Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy. | |
| Title | PictShare < 3.7.1 Sensitive Information Disclosure via info API | |
| First Time appeared |
Hascheksolutions
Hascheksolutions pictshare |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hascheksolutions
Hascheksolutions pictshare |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T21:08:37.900Z
Reserved: 2026-10-01T17:52:44.371Z
Link: CVE-2026-104051
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-522
Insufficiently Protected Credentials