pH7Builder(pH7 Social Dating CMS)在 18.5.0 版本之前存在一个“身份验证尝试限制不当”的安全漏洞,攻击者可通过无限制地猜测基于时间的一次性密码(TOTP)代码,从而绕过双因素身份验证。已知某个账户密码的攻击者可以向 VerificationCodeFormProcess.php 提交无限数量的 6 位验证代码,进而接管会员、联盟会员或管理员账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ph7software | ph7builder | 0 ~ 18.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107636 | 6.5 MEDIUM | pH7Builder before 18.5.1 Payment Bypass via Payment Module MainController |
| CVE-2026-107637 | 4.3 MEDIUM | pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action |
No comments yet