Sceawere
Vulnerability Detail
CVE-2026-108902UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
pH7Builder Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 3h ago
- Vendor
- ph7software
- Product
- ph7builder
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-11T15:16:56.337Z",
"pubdate": "2026-10-11T15:16:56.337Z",
"executiveSummary": "pH7Builder, a social dating CMS, contains a critical path traversal vulnerability in versions prior to 18.5.0. The vulnerability exists within the picture module's deletePhoto() action, which improperly sanitizes user-supplied input.\nBy manipulating the picture_link parameter, an authenticated member can escape the intended application directory and delete arbitrary files on the underlying filesystem.\nThis flaw grants an authenticated attacker the capability to perform unauthorized file deletions, leading to catastrophic content loss, destruction of configuration files, and potential denial-of-service (DoS) conditions by rendering the application inoperable.\nThe vulnerability is exploitable by any authenticated user, necessitating restricted access controls and strict input validation. The lack of path canonicalization and validation allows the traversal sequences to reach files outside the intended user photo repository, exposing critical system files to deletion.",
"technicalDetails": "The vulnerability originates in the deletePhoto() action within the pH7Builder picture module. The root cause is a failure to implement proper input validation or path sanitization for the picture_link parameter before passing it to filesystem removal functions.\nThe application expects this parameter to represent a legitimate path within the user-accessible image storage directory. However, the software fails to check for directory traversal sequences (such as ../) within the supplied string, allowing the input to influence the file path resolution process outside the sandbox.\nAn authenticated attacker can craft a POST request containing a malicious payload in the picture_link parameter, utilizing multiple parent directory references. By iterating through these sequences, the attacker traverses the file system hierarchy from the initial storage directory to sensitive locations.\nThe exploitation flow proceeds as follows: 1) The attacker authenticates to the pH7Builder platform to gain access to the photo management functionality. 2) The attacker identifies the deletePhoto() request structure, typically triggered via the application UI or an intercepted HTTP request. 3) The attacker modifies the picture_link parameter to include a path traversal payload, such as '../' repeated multiple times followed by the target file name or path. 4) The server-side code receives this input and executes a file deletion operation, such as unlink(), using the unvalidated path. 5) The operating system resolves the traversal, granting the attacker the ability to target any file the web server process has permission to delete.\nThis vulnerability is particularly severe because the web server process frequently maintains write/delete permissions over configuration files, cache directories, and core application files. Successful exploitation results in the permanent deletion of these resources. Targeted destruction of configuration files, such as database credentials or main config files, forces an application failure, effectively causing a permanent denial of service. Furthermore, the deletion of cached files or site assets results in significant data and content loss. Because the application fails to enforce constraints on the depth or location of the directory traversal, the impact is limited only by the privileges of the web server service account on the hosting server."
}