CVE-2026-37603: PH7Software pH7Builder vulnerability
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captchaadminenabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote unauthenticated attacker can exploit it against the administration login. They do not need an existing account or authenticated access.
What does an attacker need to do to bypass the CAPTCHA escalation?
The attacker needs to obtain a new PHP session before each login attempt. Because the captcha_admin_enabled flag is stored in the session, a fresh session prevents the CAPTCHA form element from being built.
Is the administration login protected by CAPTCHA by default after repeated failed attempts?
The CAPTCHA escalation can be bypassed when each login attempt uses a new session. In that scenario, the attacker is not presented with the CAPTCHA challenge despite repeated attempts.
Which versions are affected?
pH7Software pH7Builder, also identified as pH7 Social Dating CMS, is affected through version 19.2.0.