Description
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Improper Authorization that permits deletion of other users’ note comments and categories
Action: Apply patch
AI Analysis

Impact

pH7Builder before version 18.5.0 contains an improper authorization flaw in the note module’s delete() action, allowing any authenticated member to delete any other member’s note comments and categories. The misuse of the POST id parameter bypasses owner checks, enabling mass removal of data associated with the targeted note ID. This vulnerability maps to CWE‑639 and results in loss of data integrity without exposing remote code execution or privilege escalation beyond the CMS context.

Affected Systems

The affected product is ph7builder from ph7software. All releases prior to 18.5.0, including 18.4.1 and earlier, are impacted. The flaw resides in the note module’s delete function, which is accessible to any authenticated user who can view or edit notes.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and no EPSS data is provided. The vulnerability is not listed in CISA’s KEV catalog. An attacker must be authenticated and possess general note‑access rights; once authenticated, the attacker can supply arbitrary note IDs via POST to delete other users’ content. This leads to intentional loss of user data and potential service disruption but does not compromise system confidentiality or availability beyond the CMS.

Generated by OpenCVE AI on October 8, 2026 at 16:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to pH7Builder 18.5.0 or newer, where the delete action verifies the owner’s profile ID before execution.
  • If an upgrade is not immediately possible, restrict the delete permission to administrator roles or enforce server‑side checks that confirm the authenticated user’s ID matches the note owner.
  • Implement a web‑application firewall rule that blocks or alerts on POST requests containing a note ID that does not belong to the authenticated session, mitigating accidental or malicious data deletion.

Generated by OpenCVE AI on October 8, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Ph7software
Ph7software ph7builder
Vendors & Products Ph7software
Ph7software ph7builder

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks.
Title pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ph7software Ph7builder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:47:57.461Z

Reserved: 2026-10-08T14:06:00.033Z

Link: CVE-2026-107637

cve-icon Vulnrichment

Updated: 2026-10-08T14:47:53.297Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:46.737

Modified: 2026-10-08T15:17:46.873

Link: CVE-2026-107637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key