CVE-2026-107637: pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pH7Builderto a version that resolves this vulnerability.Fixed in 18.5.0
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be an authenticated pH7Builder member. No user interaction is required.
What can an attacker change through the vulnerable action?
An authenticated member can submit another member's note ID in the POST id parameter. This can remove that note's comments and category associations.
Which installations should be remediated?
pH7Builder versions before 18.5.0 are affected. Upgrade to 18.5.0 or later.