Sceawere
Vulnerability Detail
CVE-2026-108904UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
pH7Builder Sensitive Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- ph7software
- Product
- ph7builder
- Attack Type
- Insufficiently Protected Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-11T15:16:56.640Z",
"pubdate": "2026-10-11T15:16:56.640Z",
"executiveSummary": "pH7Builder versions prior to 18.5.0 contain an information disclosure vulnerability within the API framework.\nThe vulnerability stems from improper data filtering in API controllers, resulting in the unauthorized exposure of sensitive member records.\nAttackers possessing a valid private API key can extract critical credentials, including bcrypt password hashes, persistent hashValidation tokens, and TOTP secrets.\nSuccessful exploitation allows for full account takeover and the circumvention of two-factor authentication (2FA) mechanisms.\nThe flaw impacts the integrity and confidentiality of user profiles, posing a significant risk to site security and user privacy.\nExploitation requires initial access to a valid private API key, which may be obtained through secondary vulnerabilities or misconfigurations.\nThe risk is categorized as high due to the potential for automated mass exploitation of user credentials and the direct bypass of security controls.",
"technicalDetails": "The vulnerability is rooted in the UserController class of the pH7 Social Dating CMS, specifically within the users() and user() functions.\nThese functions fail to sanitize database results before serializing them for API responses, directly returning raw database rows containing sensitive metadata intended only for internal application processing.\nThe flaw manifests because the controller lacks a projection or data transfer object (DTO) layer to strip restricted fields from the database query result set.\nWhen an API client executes a request to these endpoints, the application performs an unconstrained database query and transmits the full object state to the requester.\nThe exposed data include bcrypt-hashed passwords, non-expiring hashValidation tokens used for account recovery, and TOTP (Time-based One-Time Password) configuration secrets.\nThe attack flow proceeds as follows: First, the adversary authenticates via the API using a valid private key. Second, the adversary sends a request to the vulnerable endpoints (users() or user()). Third, the server fetches the user record, including sensitive fields, from the underlying database. Finally, the application returns the raw object to the attacker without filtering, exposing the cryptographic material.\nPost-exploitation, an attacker can utilize the leaked bcrypt hashes to attempt offline brute-force or credential stuffing attacks. More critically, the availability of the TOTP secret enables the attacker to generate valid 2FA tokens, effectively nullifying the security benefits of multi-factor authentication.\nFurthermore, the non-expiring nature of the hashValidation tokens allows attackers to initiate persistent session hijacking or unauthorized password resets.\nThe issue affects all pH7Builder versions prior to 18.5.0. No specific network exposure beyond access to the API interface is required for exploitation, provided the attacker satisfies the authentication requirement of possessing a valid private API key."
}