Improper Authorization in pH7Builder Note Module Affects pH7 Social Dating CMS
CVE-2026-107637

5.3MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107637?

The pH7 Social Dating CMS, specifically in versions earlier than 18.5.0, is susceptible to an improper authorization vulnerability. This flaw resides in the note module's delete() action, permitting authenticated users to maliciously delete comments and categories linked to other users' notes. By exploiting the vulnerability, attackers can manipulate the POST id parameter to reference a note ID associated with another member. Consequently, the system fails to verify profile IDs, thus allowing unauthorized deletion of content that should be protected. This issue must be addressed to maintain user content integrity and prevent abuse.

Affected Version(s)

ph7builder 0 < 18.5.0

ph7builder 18.5.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haluk Baran AKBULUT (CyberMap Group)
.