{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-107637", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-08T14:06:00.033Z", "datePublished": "2026-10-08T14:10:34.824Z", "dateUpdated": "2026-10-08T14:47:57.461Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-08T14:10:34.824Z" }, "datePublic": "2026-07-29T00:00:00.000Z", "title": "pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action", "descriptions": [ { "lang": "en", "value": "pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Authorization Bypass Through User-Controlled Key", "cweId": "CWE-639", "type": "CWE" } ] } ], "affected": [ { "vendor": "ph7software", "product": "ph7builder", "defaultStatus": "unaffected", "packageURL": "pkg:composer/ph7software/ph7builder", "versions": [ { "version": "0", "status": "affected", "versionType": "semver", "lessThan": "18.5.0" }, { "version": "18.5.0", "status": "unaffected", "versionType": "semver" } ] } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM" } } ], "references": [ { "url": "https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/e784139b2385ef44d08a1d586c365857dd777ef6", "tags": [ "patch" ], "name": "Patch Commit" }, { "url": "https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.4.1/_protected/app/system/modules/note/controllers/MainController.php#L311-L320", "tags": [ "technical-description" ] }, { "url": "https://github.com/pH7Software/pH7-Social-Dating-CMS", "tags": [ "product" ] }, { "name": "VulnCheck Advisory: pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/ph7builder-before-18.5.0-improper-authorization-via-note-module-delete-action" } ], "credits": [ { "lang": "en", "value": "Haluk Baran AKBULUT (CyberMap Group)", "type": "finder" } ], "x_generator": { "engine": "vulncheck-endgame" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-08T14:47:39.593788Z", "id": "CVE-2026-107637", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-08T14:47:57.461Z" } } ] } }