pH7Builder(pH7 社交 dating CMS)在 18.5.0 版本之前,在 note 模块的 delete() 操作中存在不恰当的授权漏洞,允许已认证的用户删除其他用户成员的笔记评论和分类。攻击者可以通过在 POST id 参数中提交其他成员的笔记 ID 来删除其所有评论和分类关联,因为这些查询缺少对个人资料 ID 的检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ph7software | ph7builder | 0 ~ 18.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107638 | 6.8 MEDIUM | pH7Builder before 18.5.0 2FA Brute Force via VerificationCodeFormProcess.php |
| CVE-2026-107636 | 6.5 MEDIUM | pH7Builder before 18.5.1 Payment Bypass via Payment Module MainController |
No comments yet