Improper Authorization in pH7Builder Note Module Affects pH7 Social Dating CMS
CVE-2026-107637
5.3MEDIUM
What is CVE-2026-107637?
The pH7 Social Dating CMS, specifically in versions earlier than 18.5.0, is susceptible to an improper authorization vulnerability. This flaw resides in the note module's delete() action, permitting authenticated users to maliciously delete comments and categories linked to other users' notes. By exploiting the vulnerability, attackers can manipulate the POST id parameter to reference a note ID associated with another member. Consequently, the system fails to verify profile IDs, thus allowing unauthorized deletion of content that should be protected. This issue must be addressed to maintain user content integrity and prevent abuse.
Affected Version(s)
ph7builder 0 < 18.5.0
ph7builder 18.5.0
