pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ph7software
Ph7software ph7builder |
|
| Vendors & Products |
Ph7software
Ph7software ph7builder |
Sun, 11 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication. | |
| Title | pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController | |
| Weaknesses | CWE-522 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T14:58:06.113Z
Reserved: 2026-10-11T14:47:10.965Z
Link: CVE-2026-108904
No data.
Status : Deferred
Published: 2026-10-11T15:16:56.640
Modified: 2026-10-11T15:16:56.757
Link: CVE-2026-108904
No data.
OpenCVE Enrichment
Updated: 2026-10-11T16:30:17Z
Weaknesses