Description
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication.
Published: 2026-10-11
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure / Account Takeover
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from an information disclosure flaw in the UserController API where unfiltered database rows are returned. With a valid private API key, an attacker can read sensitive data such as bcrypt password hashes, non‑expiring hashValidation reset tokens, and TOTP secrets. These credentials enable account takeover and the bypass of two‑factor authentication, constituting a severe compromise of confidentiality and integrity of user accounts (CWE‑522).

Affected Systems

Affected systems are instances of ph7software’s pH7Builder CMS running any version before 18.5.0. The flaw exists in the UserController modules responsible for handling API requests to user data. No specific patch or version number is provided other than the requirement to upgrade to 18.5.0 or later.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, with exploitation possible from remote API endpoints. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet documented. However, the need for a valid private API key implies that attackers must already have legitimate credential access or have obtained keys through other means. If such keys are compromised, the exposed data can be leveraged for direct account takeover.

Generated by OpenCVE AI on October 11, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest pH7Builder release (18.5.0 or later).
  • Immediately revoke all existing private API keys, generate new keys, and restrict API endpoint access to trusted IP ranges.
  • Force a password reset for all users and require re‑authentication for existing sessions.

Generated by OpenCVE AI on October 11, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ph7software
Ph7software ph7builder
Vendors & Products Ph7software
Ph7software ph7builder

Sun, 11 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication.
Title pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ph7software Ph7builder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T14:58:06.113Z

Reserved: 2026-10-11T14:47:10.965Z

Link: CVE-2026-108904

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-11T15:16:56.640

Modified: 2026-10-11T15:16:56.757

Link: CVE-2026-108904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T16:30:17Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials