IP-based Throttling Bypass Vulnerability in pH7 Social Dating CMS
CVE-2026-37604
6.5MEDIUM
What is CVE-2026-37604?
In pH7Builder (pH7 Social Dating CMS), versions through 18.2.0, a security vulnerability exists due to inadequate verification of the source of HTTP headers. The software does not properly validate the request origins of the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers, allowing a remote unauthenticated attacker to exploit this weakness. This could enable them to bypass IP-based throttling mechanisms, which are supposed to limit login attempts by tracking the originating IP address. By manipulating the X-Forwarded-For header, attackers can effectively evade detection and lockout measures, leading to potential unauthorized access.
