Impact
The vulnerability exists in PictShare versions before 3.7.1, where the delete_code used for authorizing file removals is produced by the non‑cryptographic rand() function. Because rand() is deterministic and easily replayable, attackers can predict or infer the current generator state and generate valid delete_code values, allowing them to delete arbitrary hosted files without accessing any other information. The exploit therefore results in unauthorized data loss for the affected account and can be performed remotely as part of the standard delete request flow.
Affected Systems
Customers running PictShare from HaschekSolutions, any version older than 3.7.1, are vulnerable. The product is identified by the CPE cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*.*
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be Remote over the network because the delete operation is performed through HTTP requests that do not require privileged access. The weakness is a cryptographic failure (CWE-338), making the token generation insecure. Exploitation requires only standard HTTP requests to the delete endpoint and a predictable PRNG state, so the likelihood of successful attacks is high if attackers can observe or guess the seed.
OpenCVE Enrichment