<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PH7 Social Dating CMS (&lt; 18.6.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ph7-social-dating-cms--18.6.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 16:03:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ph7-social-dating-cms--18.6.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in pH7Builder</title><link>https://feed.craftedsignal.io/briefs/2026-10-ph7builder-path-traversal/</link><pubDate>Sun, 11 Oct 2026 16:03:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ph7builder-path-traversal/</guid><description>Authenticated users can exploit a path traversal vulnerability in the pH7Builder picture module to delete arbitrary files on the server.</description><content:encoded><![CDATA[<p>pH7 Social Dating CMS (pH7Builder) versions prior to 18.5.0 contain a critical path traversal vulnerability within the deletePhoto() action of the picture module. An authenticated member can manipulate the picture_link parameter during a file deletion request by injecting directory traversal sequences (such as ../). This flaw allows the attacker to escape the intended directory and delete arbitrary files accessible by the web server process. Successful exploitation can lead to the deletion of configuration files, cache files, or other users' media, resulting in persistent denial of service or disruption of application functionality. Organizations using this CMS should prioritize patching to version 18.5.0 or later to mitigate the risk of unauthorized file deletion and system instability.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for arbitrary file deletion on the hosting server. This impact is significant for a Content Management System, as attackers can delete critical application configuration files or site content, resulting in immediate service disruption. No specific number of victims is provided, but all internet-facing instances of pH7Builder below version 18.5.0 are currently at risk of exploitation.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade pH7 Social Dating CMS to version 18.5.0 or later immediately.</li>
<li>Implement strict input validation on the picture_link parameter within the picture module to prevent path traversal sequences.</li>
<li>Restrict file system permissions for the web server user to the minimum necessary directories to limit the scope of potential file deletions.</li>
<li>Audit web server access logs for POST requests to the picture module containing directory traversal characters (e.g., &quot;../&quot; or &quot;..\&quot;).</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>data-exfiltration</category><category>cve-2026-108905</category></item></channel></rss>