{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-108905/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ph7builder:ph7_social_dating_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-108902"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pH7 Social Dating CMS (\u003c 18.5.0)","pH7 Social Dating CMS (\u003c 18.6.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","data-exfiltration","cve-2026-108905"],"_cs_type":"advisory","_cs_vendors":["pH7Builder"],"content_html":"\u003cp\u003epH7 Social Dating CMS (pH7Builder) versions prior to 18.5.0 contain a critical path traversal vulnerability within the deletePhoto() action of the picture module. An authenticated member can manipulate the picture_link parameter during a file deletion request by injecting directory traversal sequences (such as ../). This flaw allows the attacker to escape the intended directory and delete arbitrary files accessible by the web server process. Successful exploitation can lead to the deletion of configuration files, cache files, or other users' media, resulting in persistent denial of service or disruption of application functionality. Organizations using this CMS should prioritize patching to version 18.5.0 or later to mitigate the risk of unauthorized file deletion and system instability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for arbitrary file deletion on the hosting server. This impact is significant for a Content Management System, as attackers can delete critical application configuration files or site content, resulting in immediate service disruption. No specific number of victims is provided, but all internet-facing instances of pH7Builder below version 18.5.0 are currently at risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade pH7 Social Dating CMS to version 18.5.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the picture_link parameter within the picture module to prevent path traversal sequences.\u003c/li\u003e\n\u003cli\u003eRestrict file system permissions for the web server user to the minimum necessary directories to limit the scope of potential file deletions.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for POST requests to the picture module containing directory traversal characters (e.g., \u0026quot;../\u0026quot; or \u0026quot;..\\\u0026quot;).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T16:03:26Z","date_published":"2026-10-11T16:03:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ph7builder-path-traversal/","summary":"Authenticated users can exploit a path traversal vulnerability in the pH7Builder picture module to delete arbitrary files on the server.","title":"Path Traversal Vulnerability in pH7Builder","url":"https://feed.craftedsignal.io/briefs/2026-10-ph7builder-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-108905","version":"https://jsonfeed.org/version/1.1"}