Vendor
PictShare versions prior to 3.7.1 contain a vulnerability where insecure PRNG usage for delete_code generation allows unauthenticated attackers to delete arbitrary files from hosted instances.