PictShare 版本低于 3.7.1 存在弱随机性漏洞。其中, 文件中的 函数使用非密码学安全的 伪随机数生成器(PRNG)来生成 授权令牌。攻击者可以预测或推断该 PRNG 的内部状态,从而猜测出有效的 值,并在无需从 info 端点读取代码的情况下,未经授权地删除托管文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HaschekSolutions | pictshare | 2.0.0 ~ 3.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet