Information Disclosure Vulnerability in PictShare by Haschek Solutions
CVE-2026-104051
8.8HIGH
What is CVE-2026-104051?
PictShare versions before 3.7.1 are susceptible to information disclosure due to an API vulnerability that exposes sensitive uploader data. Unauthenticated attackers can exploit this weakness by invoking the API::info() endpoint. This action returns comprehensive metadata, including the delete_code, which allows unauthorized file deletions. The risk involves not only the unauthorized deletion of files but also the exposure of uploader details such as IP address, User Agent, remote port, and file hash, compromising user privacy and data integrity.
Affected Version(s)
pictshare 2.0.0 < 3.7.1
