CVE-2026-37603 Details
Description
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.
A vulnerability exists in pH7Software pH7Builder (pH7 Social Dating CMS) versions through 19.2.0, allowing remote unauthenticated attackers to bypass CAPTCHA protections on the administration login. The issue arises because the CAPTCHA escalation flag, 'captcha_admin_enabled', is stored in the PHP session. When this flag is present, the CAPTCHA challenge is presented to the user. However, an attacker who obtains a new session before each login attempt can exploit this behavior to avoid the CAPTCHA challenge altogether.
Users can upgrade to pH7Builder version 19.3.1, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cybermapgroup.com/en/blog/admin-brute-force-protection-bypass-chain-in-ph7builder | CISA-ADP | ExploitTechnical Description |
| https://cybermapgroup.com/en/blog/admin-brute-force-protection-bypass-chain-in-ph7builder | [email protected] | ExploitTechnical Description |
| https://github.com/pH7Software/pH7-Social-Dating-CMS | [email protected] | Source CodeVendor |
| https://ph7builder.com | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| pH7Software pH7Builder | <= 19.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | [email protected] |
Volerion