Tag
PictShare versions prior to 3.7.1 are vulnerable to an unauthenticated information disclosure flaw in the API::info() endpoint, allowing attackers to retrieve sensitive metadata and delete arbitrary files.