PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint. | |
| Title | PictShare < 3.7.1 Predictable Delete Code via rand() | |
| First Time appeared |
Hascheksolutions
Hascheksolutions pictshare |
|
| Weaknesses | CWE-338 | |
| CPEs | cpe:2.3:a:hascheksolutions:pictshare:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hascheksolutions
Hascheksolutions pictshare |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T21:21:45.992Z
Reserved: 2026-10-01T20:48:03.271Z
Link: CVE-2026-104356
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses