Impact
PictShare versions prior to 3.7.1 expose a REST API endpoint that returns the complete raw metadata for any file, including a delete code, uploader IP, user agent, remote port, and hash. An unauthenticated attacker can call the API::info() endpoint to obtain this data, enabling the attacker to permanently delete files via the delete API and to expose uploader privacy and location data. The vulnerability is categorized as CWE‑522, Information Exposure.
Affected Systems
Affected systems are deployments of HaschekSolutions PictShare with any version earlier than 3.7.1. The product is identified by the vendor name HaschekSolutions.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. Because the API is unauthenticated, the likely attack vector is remote over the network where the PictShare instance is exposed, allowing an attacker to retrieve sensitive data and delete arbitrary files without authorization.
OpenCVE Enrichment