CVE-2026-37603: PH7Software pH7Builder vulnerability

Published Sep 22, 2026
·
Updated

Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captchaadminenabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.

Affected Software

1 affected component
pH7Software pH7Builder<=19.2.0

Event History

Sep 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
Description

Frequently Asked Questions

1

Who can exploit this issue?

A remote unauthenticated attacker can exploit it against the administration login. They do not need an existing account or authenticated access.

2

What does an attacker need to do to bypass the CAPTCHA escalation?

The attacker needs to obtain a new PHP session before each login attempt. Because the captcha_admin_enabled flag is stored in the session, a fresh session prevents the CAPTCHA form element from being built.

3

Is the administration login protected by CAPTCHA by default after repeated failed attempts?

The CAPTCHA escalation can be bypassed when each login attempt uses a new session. In that scenario, the attacker is not presented with the CAPTCHA challenge despite repeated attempts.

4

Which versions are affected?

pH7Software pH7Builder, also identified as pH7 Social Dating CMS, is affected through version 19.2.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203