CVE-2026-108905

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,7
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none

Description

AI Translation Available

pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields.

798

Use of Hard-coded Credentials

Draft
Common Consequences
Security Scopes Affected:
Access Control Integrity Confidentiality Availability Other
Potential Impacts:
Bypass Protection Mechanism Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands Other
Applicable Platforms
Technologies: Mobile, ICS/OT
View CWE Details
https://github.com/pH7Software/pH7-Social-Dating-CMS
https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v18.5.1/_protected/fr…
https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/cfe1e0c418946b868db…
https://www.vulncheck.com/advisories/ph7builder-before-18.6.0-hard-coded-api-ke…