Impact
The vulnerability stems from an information disclosure flaw in the UserController API where unfiltered database rows are returned. With a valid private API key, an attacker can read sensitive data such as bcrypt password hashes, non‑expiring hashValidation reset tokens, and TOTP secrets. These credentials enable account takeover and the bypass of two‑factor authentication, constituting a severe compromise of confidentiality and integrity of user accounts (CWE‑522).
Affected Systems
Affected systems are instances of ph7software’s pH7Builder CMS running any version before 18.5.0. The flaw exists in the UserController modules responsible for handling API requests to user data. No specific patch or version number is provided other than the requirement to upgrade to 18.5.0 or later.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, with exploitation possible from remote API endpoints. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet documented. However, the need for a valid private API key implies that attackers must already have legitimate credential access or have obtained keys through other means. If such keys are compromised, the exposed data can be leveraged for direct account takeover.
OpenCVE Enrichment