💨 Abstract

A security researcher, Zeacer, discovered a flaw in Hama Film's photo booth website that exposed customers' photos and videos online. The vulnerability allows access to files stored on the company's servers, which upload images from their photo booths. Despite being alerted in October, Hama Film and its parent company, Vibecast, have not fully resolved the issue. The flaw limits the number of exposed pictures by deleting them after 24 hours, but it remains exploitable.

Courtesy: Lorenzo Franceschi-Bicchierai