CVE-2026-108903

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,9
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse.

807

Reliance on Untrusted Inputs in a Security Decision

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Access Control Availability Other
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity Varies By Context
Applicable Platforms
Technologies: Not Technology-Specific, Web Based, Web Server
View CWE Details
https://github.com/pH7Software/pH7-Social-Dating-CMS
https://github.com/pH7Software/pH7-Social-Dating-CMS/blob/v19.2.0/_protected/ap…
https://github.com/pH7Software/pH7-Social-Dating-CMS/commit/4758d7d2ebfd5772faa…
https://www.vulncheck.com/advisories/ph7builder-before-19.3.0-captcha-bypass-vi…