CyberRota Analysis
AI-GeneratedPictShare versions prior to 3.7.1 are vulnerable to an information disclosure flaw that enables unauthenticated attackers to access sensitive uploader metadata and the secret delete_code through the API::info() endpoint. This vulnerability allows attackers to delete arbitrary files and exposes critical information such as uploader IP addresses and User Agents, compromising content integrity and privacy. Organizations using PictShare should prioritize patching to mitigate the risk of data loss and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.