Path Traversal Vulnerability in pH7Builder
Authenticated users can exploit a path traversal vulnerability in the pH7Builder picture module to delete arbitrary files on the server.
CVE search metadata
CVE search record: CVE-2026-108902. Severity: high. CVSS: 8.1. KEV: no. Product: pH7 Social Dating CMS (< 18.5.0), pH7 Social Dating CMS (< 18.6.0). Brief: Path Traversal Vulnerability in pH7Builder. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ph7builder-path-traversal/
What's new
- 1. added coverage for pH7 Social Dating CMS (< 18.6.0) Oct 11, 16:03 via nvd
pH7 Social Dating CMS (pH7Builder) versions prior to 18.5.0 contain a critical path traversal vulnerability within the deletePhoto() action of the picture module. An authenticated member can manipulate the picture_link parameter during a file deletion request by injecting directory traversal sequences (such as ../). This flaw allows the attacker to escape the intended directory and delete arbitrary files accessible by the web server process. Successful exploitation can lead to the deletion of configuration files, cache files, or other users' media, resulting in persistent denial of service or disruption of application functionality. Organizations using this CMS should prioritize patching to version 18.5.0 or later to mitigate the risk of unauthorized file deletion and system instability.
Impact
The vulnerability allows for arbitrary file deletion on the hosting server. This impact is significant for a Content Management System, as attackers can delete critical application configuration files or site content, resulting in immediate service disruption. No specific number of victims is provided, but all internet-facing instances of pH7Builder below version 18.5.0 are currently at risk of exploitation.
Recommendation
- Upgrade pH7 Social Dating CMS to version 18.5.0 or later immediately.
- Implement strict input validation on the picture_link parameter within the picture module to prevent path traversal sequences.
- Restrict file system permissions for the web server user to the minimum necessary directories to limit the scope of potential file deletions.
- Audit web server access logs for POST requests to the picture module containing directory traversal characters (e.g., "../" or "..\").
Immediate actions
Upgrade pH7 Social Dating CMS to 18.5.0 or later.
Threat Hunt
Search logs for POST requests to the pH7Builder picture module containing '../' or '..\'.
Data: Webserver access logs
Mitigations
Upgrade to version 18.5.0.
CVE-2026-108902
Detection coverage 1
Detect CVE-2026-108902 Exploitation - Path Traversal in pH7Builder
highDetects exploitation attempts by identifying directory traversal sequences in the picture_link parameter within POST requests.
Detection queries are available on the platform. Get full rules →