Impact
pH7Builder before version 18.5.0 contains a path traversal flaw in the deletePhoto action of the picture module that lets authenticated users supply a POST picture_link parameter with ".." sequences to delete files outside the intended photo directory. This flaw can cause loss of photos, configuration, and cache files, resulting in data loss and service disruption.
Affected Systems
The vulnerability affects installations of the ph7software ph7builder CMS version 18.4.x and any earlier releases. Users of pH7Builder running a version earlier than 18.5.0 are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity due to potential for file destruction. The EPSS score is not available, but the vulnerability is not listed in CISA KEV. Attackers must be authenticated members; they can trigger the flaw by posting a carefully crafted picture_link parameter. Once exploited, the attacker can delete arbitrary system files, compromising data integrity and availability.
OpenCVE Enrichment