IP-based Throttling Bypass Vulnerability in pH7 Social Dating CMS
CVE-2026-37604

6.5MEDIUM

Key Information:

Vendor
CVE Published:
22 September 2026

What is CVE-2026-37604?

In pH7Builder (pH7 Social Dating CMS), versions through 18.2.0, a security vulnerability exists due to inadequate verification of the source of HTTP headers. The software does not properly validate the request origins of the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers, allowing a remote unauthenticated attacker to exploit this weakness. This could enable them to bypass IP-based throttling mechanisms, which are supposed to limit login attempts by tracking the originating IP address. By manipulating the X-Forwarded-For header, attackers can effectively evade detection and lockout measures, leading to potential unauthorized access.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.