Path Traversal Vulnerability in pH7 Social Dating CMS by pH7 Software
CVE-2026-108902
7.2HIGH
What is CVE-2026-108902?
The pH7 Social Dating CMS prior to version 18.5.0 is susceptible to a path traversal vulnerability in the picture module's deletePhoto() action. This vulnerability enables authenticated users to manipulate the POST parameter 'picture_link' to include '../' sequences, potentially allowing them to delete arbitrary files. As a result, this can lead to unauthorized deletion of other users' photos or critical configuration and cache files, causing loss of content and creating denial of service conditions. Users are advised to update to the latest version to mitigate this risk.
Affected Version(s)
ph7builder 0 < 18.5.0
ph7builder 18.5.0
