Hard-Coded API Key Vulnerability in pH7Builder from pH7 Software
CVE-2026-108905
8.7HIGH
What is CVE-2026-108905?
The pH7Builder, a social dating CMS provided by pH7 Software, features a vulnerability where an attacker can exploit a hard-coded API key in Tool.class.php. This issue allows unauthenticated users to bypass API access checks by spoofing the Host header, specifically by sending a request with 'Host: localhost' and the private API key 'dev772277'. This vulnerability could expose sensitive information such as member emails, IP addresses, phone numbers, and bank account details, posing a significant risk to user privacy and data security.
Affected Version(s)
ph7builder 0 < 18.6.0
ph7builder 18.6.0
