← Back to search

CVE-2026-37604

9.8 CRITICALpublic exploit available

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows remote unauthenticated attackers to bypass IP-based throttling by manipulating the X-Forwarded-For header, leading to potential unauthorized access to admin functionalities.
Exploitability
Exploitation is relatively straightforward as attackers can send a different X-Forwarded-For value per request, requiring no specific preconditions other than the ability to modify HTTP headers.
Blast radius
If exploited, this could lead to unauthorized access to admin features, potentially resulting in data breaches or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to pH7Builder version 18.3.0 or later.
auth-bypasswebheader-manipulation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the admin login attempt counter and lockout are keyed on this value, a remote unauthenticated attacker bypasses IP-based throttling by sending a different X-Forwarded-For value per request

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-444

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.