Information Disclosure in pH7Builder by pH7 Software
CVE-2026-108904
7.1HIGH
What is CVE-2026-108904?
pH7Builder, a social dating CMS developed by pH7 Software, is impacted by an information disclosure flaw. This vulnerability allows API clients to access sensitive member information, including bcrypt password hashes, reset tokens, and TOTP secrets. Attackers with a valid private API key can exploit the unfiltered data returned by the UserController::users() and user() methods, potentially leading to account takeovers and the circumvention of two-factor authentication. It is crucial for users to update to version 18.5.0 or later to mitigate this risk.
Affected Version(s)
ph7builder 0 < 18.5.0
ph7builder 18.5.0
