Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an improper authorization vulnerability in the note module delete() action that allows authenticated members to delete other members' note comments and categories. Attackers can submit another member's note ID in the POST id parameter to remove all comments and category associations, since those queries lack profile ID checks. | |
| Title | pH7Builder before 18.5.0 Improper Authorization via Note Module delete() Action | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T14:47:57.461Z
Reserved: 2026-10-08T14:06:00.033Z
Link: CVE-2026-107637
Updated: 2026-10-08T14:47:53.297Z
Status : Deferred
Published: 2026-10-08T15:17:46.737
Modified: 2026-10-08T15:17:46.873
Link: CVE-2026-107637
No data.
OpenCVE Enrichment
No data.