---
id: CVE-2026-37603
title: >-
  Improper Restriction of Excessive Authentication Attempts in the
  administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through
  19.2.0
summary: >-
  Improper Restriction of Excessive Authentication Attempts in the
  administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through
  19.2.0. The CAPTCHA escalation flag is stored in the PHP session as
  captcha_admin_enabled and…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-307
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:15.373'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-37603'
references:
  - url: >-
      https://cybermapgroup.com/en/blog/admin-brute-force-protection-bypass-chain-in-ph7builder
    label: cve@mitre.org
  - url: 'https://github.com/pH7Software/pH7-Social-Dating-CMS'
    label: cve@mitre.org
  - url: 'https://ph7builder.com'
    label: cve@mitre.org
  - url: >-
      https://cybermapgroup.com/en/blog/admin-brute-force-protection-bypass-chain-in-ph7builder
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-23T16:58:26.786453Z'
epss: 0.00497
epssPercentile: 0.40036
ingestedAt: '2026-09-22T19:09:10.005Z'
---

## Overview

Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
