在 pH7Builder(pH7 Social Dating CMS)18.5.1 版本之前,存在一个支付验证漏洞,允许权限较低的注册用户通过提供客户端可控制的计划和金额字段,获取任意会员等级。攻击者可以在支付少量代币时设置 item_number、cart_order_id 或 PayPal 自定义字段,或者提交未完成的 PayPal IPN(即时付款通知)支付,从而获得最昂贵的会员等级及其付费功能。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ph7software | ph7builder | < 18.5.1 |
affected |
18.5.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ph7software | ph7builder | 0 ~ 18.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107638 | 6.8 MEDIUM | pH7Builder before 18.5.0 2FA Brute Force via VerificationCodeFormProcess.php |
| CVE-2026-107637 | 4.3 MEDIUM | pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action |
No comments yet