CVE-2026-37603: n/a
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.
AI Analysis
Technical Summary
This vulnerability involves improper restriction of excessive authentication attempts on the administration login of pH7Builder through version 19.2.0. The CAPTCHA escalation mechanism depends on a PHP session flag captcha_admin_enabled. Since this flag is stored in the session and the CAPTCHA form is only presented when the flag is set, an unauthenticated remote attacker can evade the CAPTCHA by acquiring a new session for each login attempt, effectively bypassing the CAPTCHA protection.
Potential Impact
The vulnerability allows an attacker to perform unlimited authentication attempts without being challenged by CAPTCHA, potentially facilitating brute force attacks against the administration login. However, no known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing additional rate limiting or monitoring on the administration login to detect and block excessive authentication attempts.
CVE-2026-37603: n/a
Description
Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.
Affected software
pkg:github/ph7software/pH7-Social-Dating-CMSRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper restriction of excessive authentication attempts on the administration login of pH7Builder through version 19.2.0. The CAPTCHA escalation mechanism depends on a PHP session flag captcha_admin_enabled. Since this flag is stored in the session and the CAPTCHA form is only presented when the flag is set, an unauthenticated remote attacker can evade the CAPTCHA by acquiring a new session for each login attempt, effectively bypassing the CAPTCHA protection.
Potential Impact
The vulnerability allows an attacker to perform unlimited authentication attempts without being challenged by CAPTCHA, potentially facilitating brute force attacks against the administration login. However, no known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing additional rate limiting or monitoring on the administration login to detect and block excessive authentication attempts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-04-06T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6ab2cd74f7a7c54106997e9e
Added to database: 09/22/2026, 18:48:20 UTC
Last enriched: 09/22/2026, 19:03:26 UTC
Last updated: 09/23/2026, 02:04:30 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.