Impact
pH7Builder before version 18.5.0 contains an improper authorization flaw in the note module’s delete() action, allowing any authenticated member to delete any other member’s note comments and categories. The misuse of the POST id parameter bypasses owner checks, enabling mass removal of data associated with the targeted note ID. This vulnerability maps to CWE‑639 and results in loss of data integrity without exposing remote code execution or privilege escalation beyond the CMS context.
Affected Systems
The affected product is ph7builder from ph7software. All releases prior to 18.5.0, including 18.4.1 and earlier, are impacted. The flaw resides in the note module’s delete function, which is accessible to any authenticated user who can view or edit notes.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and no EPSS data is provided. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be authenticated and possess general note‑access rights; once authenticated, the attacker can supply arbitrary note IDs via POST to delete other users’ content. This leads to intentional loss of user data and potential service disruption but does not compromise system confidentiality or availability beyond the CMS.
OpenCVE Enrichment