Description
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service.
Published: 2026-10-11
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Authenticated Path Traversal Leading to Arbitrary File Deletion and Denial of Service
Action: Patch Immediately
AI Analysis

Impact

pH7Builder before version 18.5.0 contains a path traversal flaw in the deletePhoto action of the picture module that lets authenticated users supply a POST picture_link parameter with ".." sequences to delete files outside the intended photo directory. This flaw can cause loss of photos, configuration, and cache files, resulting in data loss and service disruption.

Affected Systems

The vulnerability affects installations of the ph7software ph7builder CMS version 18.4.x and any earlier releases. Users of pH7Builder running a version earlier than 18.5.0 are at risk.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity due to potential for file destruction. The EPSS score is not available, but the vulnerability is not listed in CISA KEV. Attackers must be authenticated members; they can trigger the flaw by posting a carefully crafted picture_link parameter. Once exploited, the attacker can delete arbitrary system files, compromising data integrity and availability.

Generated by OpenCVE AI on October 11, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pH7Builder to version 18.5.0 or later.
  • Restrict the deletePhoto functionality to administrators or disable it for non‑admin users.
  • Enforce strict file permission checks on the filesystem to prevent deletion of files outside the dedicated photo directory.

Generated by OpenCVE AI on October 11, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Ph7software
Ph7software ph7builder
Vendors & Products Ph7software
Ph7software ph7builder

Sun, 11 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service.
Title pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ph7software Ph7builder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:58:04.894Z

Reserved: 2026-10-11T14:47:05.981Z

Link: CVE-2026-108902

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T15:16:56.337

Modified: 2026-10-11T15:16:56.447

Link: CVE-2026-108902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T17:15:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')